2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-40352HIGH8.8FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to N...
CVE-2026-40321HIGH8DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2026-40527HIGH8.5radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ...
CVE-2026-40303HIGH7.5zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, endpoints.GetSessionCoo...
CVE-2026-40286HIGH7.5WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vul...
CVE-2026-40285HIGH8.8WeGIA is a web manager for charitable institutions. Versions prior to 3.6.10 contain a SQL injection vulnerability in da...
CVE-2026-40196HIGH8.1HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultG...
CVE-2026-35603HIGH7.3Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide defaul...
CVE-2026-35512HIGH8.8xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynam...
CVE-2026-40461HIGH7.5Anviz CX2 Lite and CX7 are vulnerable to unauthenticated POST requests that modify debug settings (e.g., enabling SSH),...
CVE-2026-40434HIGH8.1Anviz CrossChex Standard lacks source verification in the client/server channel, enabling TCP packet injection by an at...
CVE-2026-40283HIGH7.6WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vul...
CVE-2026-40066HIGH8.8Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and execute...
CVE-2026-35682HIGH8.8Anviz CX2 Lite is vulnerable to an authenticated command injection via a filename parameter that enables arbitrary comm...
CVE-2026-35215HIGH7.5Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the sdl_...
CVE-2026-34232HIGH7.5Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr_...
CVE-2026-32650HIGH7.5Anviz CrossChex Standard is vulnerable when an attacker manipulates the TDS7 PreLogin to disable encryption, causing da...
CVE-2026-32623HIGH8.1xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in the Neu...
CVE-2026-32324HIGH7.7Anviz CX7 Firmware is  vulnerable because the application embeds reusable certificate/key material, enabling decryption...
CVE-2026-32107HIGH8.8xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle a...
CVE-2026-32105HIGH7.7xrdp is an open source RDP server. In versions through 0.10.5, xrdp does not implement verification for the Message Auth...
CVE-2026-33337HIGH7.5Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when des...
CVE-2026-28224HIGH8.2Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the...
CVE-2026-28212HIGH7.5Firebird is an open-source relational database management system. In versions prior to 6.0.0, 5.0.4, 4.0.7 and 3.0.14, w...
CVE-2026-27890HIGH8.2Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when pro...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now