2026 CVE Vulnerabilities

53,212 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-27489HIGH7.5Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, ...
CVE-2026-34604HIGH8.8Tina is a headless content management system. Prior to version 2.2.2, @tinacms/graphql uses string-based path containmen...
CVE-2026-34603HIGH8.3Tina is a headless content management system. Prior to version 2.2.2, @tinacms/cli recently added lexical path-traversal...
CVE-2026-33949HIGH8.1Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql...
CVE-2026-30273HIGH7.3pandas-ai v3.0.0 was discovered to contain a SQL injection vulnerability via the pandasai.agent.base._execute_sql_query ...
CVE-2026-20155HIGH8A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow a...
CVE-2026-20151HIGH7.3A vulnerability in the web interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated,...
CVE-2026-20094HIGH8.8A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with re...
CVE-2026-4924HIGH8.2Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier all...
CVE-2026-4828HIGH8.2Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote att...
CVE-2026-35099HIGH7.4Lakeside SysTrack Agent 11 before 11.5.0.15 has a race condition with resultant local privilege escalation to SYSTEM. Th...
CVE-2026-30573HIGH7.5A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0. The vulnerability is loc...
CVE-2026-30292HIGH8.4An arbitrary file overwrite vulnerability in Docudepot PDF Reader: PDF Viewer APP v1.0.34 allows attackers to overwrite ...
CVE-2026-30291HIGH8.4An arbitrary file overwrite vulnerability in Ora Tools PDF Reader ' Reader & Editor APPv4.3.5 allows attackers to overwr...
CVE-2026-5271HIGH7.8pymanager included the current working directory in sys.path meaning modules could be shadowed by modules in the current...
CVE-2026-35093HIGH8.8A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or ...
CVE-2026-35092HIGH7.5A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a re...
CVE-2026-35091HIGH8.2A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Co...
CVE-2026-30289HIGH8.4An arbitrary file overwrite vulnerability in Tinybeans Private Family Album App v5.9.5-prod allows attackers to overwrit...
CVE-2026-30287HIGH8.4An arbitrary file overwrite vulnerability in Deep Thought Industries ACE Scanner PDF Scanner v1.4.5 allows attackers to ...
CVE-2026-0522HIGH8.8A local file inclusion vulnerability in the upload/download flow of the VertiGIS FM application allows authenticated att...
CVE-2026-22768HIGH7.3Dell AppSync, version(s) 4.6.0, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low...
CVE-2026-22767HIGH7.3Dell AppSync, version(s) 4.6.0, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged att...
CVE-2026-24096HIGH8.8Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5...
CVE-2026-0932HIGH7.3Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now