2026 CVE Vulnerabilities

64,788 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-92593HIGH8.8Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirec...
CVE-2026-92592HIGH8.8Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun c...
CVE-2026-92582HIGH7.1AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.js...
CVE-2026-92580HIGH8.8In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClie...
CVE-2026-92578HIGH8.1WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a...
CVE-2026-92577HIGH7.5In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title...
CVE-2026-92576HIGH8.6HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the ...
CVE-2026-85469HIGH8A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docke...
CVE-2026-61592HIGH7.4djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ...
CVE-2026-61591HIGH8.1djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ...
CVE-2026-92816HIGH7.8ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to ar...
CVE-2026-92815HIGH7.5changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attac...
CVE-2026-92806HIGH8.1phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form ha...
CVE-2026-92804HIGH7.1Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token ...
CVE-2026-92801HIGH8.8cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactiv...
CVE-2026-92796HIGH8.8Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL re...
CVE-2026-92794HIGH7.5OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when one-time-password verif...
CVE-2026-92793HIGH8.1GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated use...
CVE-2026-92792HIGH7.5OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing ...
CVE-2026-92791HIGH7.5Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated att...
CVE-2026-92788HIGH8.8Coze Studio through 0.5.1 fails to validate that table names in workflow SQL customization nodes belong to the caller's ...
CVE-2026-92786HIGH7.8LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to wr...
CVE-2026-92785HIGH8.1Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist val...
CVE-2026-92784HIGH7.5@refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source co...
CVE-2026-92783HIGH8.1Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with r...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now