2026 CVE Vulnerabilities

53,091 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-32316HIGH7.5jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_strin...
CVE-2026-28291HIGH8.1simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of a...
CVE-2026-6193HIGH7.3A security flaw has been discovered in PHPGurukul Daily Expense Tracking System 1.1. Affected is an unknown function of ...
CVE-2026-6189HIGH7.3A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. The affected element is an unk...
CVE-2026-36948HIGH7.3Sourcecodester Online Thesis Archiving System v1.0 is vulnerale to SQL injection in the file /otas/view_archive.php.
CVE-2026-23891HIGH8.7Decidim is a participatory democracy framework. In versions below 0.30.5 and 0.31.0.rc1 through 0.31.0, a stored code ex...
CVE-2026-6231HIGH7.5The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could resul...
CVE-2026-6188HIGH7.3A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function of the ...
CVE-2026-6187HIGH7.3A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. This issue affects some unknown ...
CVE-2026-6186HIGH8.8A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This vulnerability affects the functi...
CVE-2026-34188HIGH7.2Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Event Re...
CVE-2026-34186HIGH8.8Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via custom fields....
CVE-2026-30813HIGH8.8Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via module search....
CVE-2026-30809HIGH8.8Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via WebServe...
CVE-2026-30806HIGH8.8Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Network ...
CVE-2026-30804HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability allows Remote Code Execution via file upload. This issue a...
CVE-2026-6183HIGH7.3A security flaw has been discovered in code-projects Simple Content Management System 1.0. Affected by this issue is som...
CVE-2026-6182HIGH7.3A vulnerability was identified in code-projects Simple Content Management System 1.0. Affected by this vulnerability is ...
CVE-2026-33858HIGH8.8Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing t...
CVE-2026-31281HIGH8Totara LMS v19.1.5 and before is vulnerable to HTML Injection. An attacker can inject malicious HTML code in a message a...
CVE-2026-30999HIGH7.5A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Servi...
CVE-2026-30998HIGH7.5An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows att...
CVE-2026-30997HIGH7.5An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cau...
CVE-2026-1462HIGH8.8A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow S...
CVE-2026-31426HIGH7In the Linux kernel, the following vulnerability has been resolved: ACPI: EC: clean up handlers on probe failure in acp...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now