2026 CVE Vulnerabilities

52,080 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-57834CRITICAL10Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Ser...
CVE-2026-41920CRITICAL9.3Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 th...
CVE-2026-35226HIGH7.1An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same n...
CVE-2026-33930HIGH8.2Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handl...
CVE-2026-33267CRITICAL9.1Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 ...
CVE-2026-24033MEDIUM5.3Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic Server....
CVE-2026-22068MEDIUM5.3Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: fr...
CVE-2026-18197MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allow...
CVE-2026-18192HIGH7.1VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to e...
CVE-2026-18191CRITICAL9.8VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to...
CVE-2026-63242MEDIUM4.3A business logic vulnerability in Koollab LMS allowed an authenticated learner to set their lesson completion status to ...
CVE-2026-63241LOW3.1An insecure direct object reference vulnerability in Koollab LMS allowed an authenticated user to query the course compl...
CVE-2026-63240MEDIUM4.3An information disclosure vulnerability in Koollab LMS allowed an authenticated learner to obtain correct quiz answers f...
CVE-2026-63239MEDIUM5.4A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 bucke...
CVE-2026-63238MEDIUM6.5An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, incl...
CVE-2026-63237MEDIUM4.8A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled s...
CVE-2026-63236LOW3.7An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name,...
CVE-2026-63235LOW3.7An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forcibly terminate the se...
CVE-2026-63234CRITICAL9.9A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject thro...
CVE-2026-63233CRITICAL9.9A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject thro...
CVE-2026-63232CRITICAL9.9A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject thro...
CVE-2026-63231HIGH8.1A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based...
CVE-2026-63230CRITICAL9.1A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read ...
CVE-2026-63229CRITICAL9.1A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-...
CVE-2026-63228LOW2.6An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now