2026 CVE Vulnerabilities

53,163 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-51244Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-17612MEDIUM6.9Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14.20260207 contains...
CVE-2026-16481HIGH8.4A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch...
CVE-2026-12383HIGH7.5A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access control...
CVE-2026-10683MEDIUM4.6In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating in target/slave mode, the rx_full interrupt handl...
CVE-2026-10682HIGH7.8The userspace verifier z_vrfy_log_filter_set() for the log_filter_set syscall in subsys/logging/log_mgmt.c performed a s...
CVE-2026-66030MEDIUM5.4Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authen...
CVE-2026-66029MEDIUM5.4Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authent...
CVE-2026-66028HIGH7.1Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authe...
CVE-2026-64645MEDIUM6.1Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-64644MEDIUM5.3Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-64643MEDIUM5.3Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-64642HIGH8.2Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted reque...
CVE-2026-64641HIGH7.5Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-59239HIGH8.6Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authe...
CVE-2026-55579CRITICAL9.8Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor s...
CVE-2026-55578HIGH8.8Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, the termin...
CVE-2026-54540HIGH8.8Pheditor is a single-file editor and file manager written in PHP. Prior to version 2.0.5, there is an authenticated term...
CVE-2026-54272MEDIUM6.9ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2...
CVE-2026-51235Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-48052MEDIUM5.4Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who i...
CVE-2026-48051LOW3.5Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, Papra's webhook delivery sy...
CVE-2026-48030CRITICAL9.9Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Comm...
CVE-2026-45623CRITICAL9.1PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract ...
CVE-2026-17570MEDIUM4.3Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileg...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now