2026 CVE Vulnerabilities

53,121 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-4157HIGH7.5ChargePoint Home Flex revssh Service Command Injection Remote Code Execution Vulnerability. This vulnerability allows ne...
CVE-2026-4156HIGH7.5ChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability a...
CVE-2026-4155HIGH7.5ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability. This vulne...
CVE-2026-4154HIGH7.8GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers t...
CVE-2026-4153HIGH7.8GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a...
CVE-2026-4152HIGH7.8GIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a...
CVE-2026-4151HIGH7.8GIMP ANI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers t...
CVE-2026-4150HIGH7.8GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers t...
CVE-2026-3690HIGH7.4OpenClaw Canvas Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication...
CVE-2026-40198HIGH7.5Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP ACL bypass. _pack_...
CVE-2026-40252HIGH8.1FastGPT is an AI Agent building platform. Prior to 4.14.10.4, Broken Access Control vulnerability (IDOR/BOLA) allows any...
CVE-2026-40188HIGH7.7goshs is a SimpleHTTPServer written in Go. From 1.0.7 to before 2.0.0-beta.4, the SFTP command rename sanitizes only the...
CVE-2026-40180HIGH7.5Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to 2....
CVE-2026-40177HIGH7.5ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was a...
CVE-2026-40168HIGH8.2Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vulnerable to SSRF. Al...
CVE-2026-32252HIGH7.7Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-33710HIGH7.5Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, REST API keys are generated using md5(time...
CVE-2026-33706HIGH7.1Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user with a REST API key can modify the...
CVE-2026-33704HIGH8.8Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including students) can write arb...
CVE-2026-33702HIGH7.1Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an Insecure Direct Ob...
CVE-2026-33618HIGH8.8Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController::decodeSettingArray...
CVE-2026-40163HIGH8.2Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.5, 1.5.5, and 1.6.0-beta.4, t...
CVE-2026-40162HIGH7.1Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability was identified in Bugs...
CVE-2026-32931HIGH8.8Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an unrestricted file upload vulnerability ...
CVE-2026-32930HIGH7.1Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR)...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now