2026 CVE Vulnerabilities

52,215 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-39110HIGH8.2SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the con...
CVE-2026-6662HIGH7.3A vulnerability was found in ericc-ch copilot-api up to 0.7.0. The impacted element is the function cors of the file src...
CVE-2026-41445HIGH8.8KissFFT before commit 8a8e66e contains an integer overflow vulnerability in the kiss_fftndr_alloc() function in kiss_fft...
CVE-2026-40488HIGH8.8Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun...
CVE-2026-30266HIGH7.8Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbit...
CVE-2026-26943HIGH7.2Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r...
CVE-2026-26942HIGH7.2Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used i...
CVE-2026-25524HIGH8.1Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun...
CVE-2026-24506HIGH7.2Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r...
CVE-2026-24505HIGH7.2Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain an improper input validation vulnerability. A high privi...
CVE-2026-24504HIGH7.2Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r...
CVE-2026-22761HIGH7.2Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A high privileged att...
CVE-2026-6066HIGH7.1ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automa...
CVE-2026-41245HIGH7.5Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFold...
CVE-2026-40896HIGH7.1OpenProject is open-source, web-based project management software. Prior to version 17.3.0, a user with `manage_agendas`...
CVE-2026-34428HIGH8.3Vvveb prior to 1.0.8.1 contains a server-side request forgery vulnerability in the oEmbedProxy action of the editor/edit...
CVE-2026-34427HIGH8.8Vvveb prior to 1.0.8.1 contains a privilege escalation vulnerability in the admin user profile save endpoint that allows...
CVE-2026-26944HIGH8.8Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r...
CVE-2026-25058HIGH7.5Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Ve...
CVE-2026-23774HIGH7.2Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,...
CVE-2026-4048HIGH7.2OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker...
CVE-2026-3519HIGH7.2OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacke...
CVE-2026-3518HIGH7.2OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacke...
CVE-2026-3517HIGH7.2OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacke...
CVE-2026-6635HIGH7.3A security vulnerability has been detected in rowboatlabs rowboat up to 0.1.67. This impacts the function tool_call of t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now