2026 CVE Vulnerabilities

53,346 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-34386HIGH8.8Fleet is open source device management software. Prior to 4.81.0, a SQL injection vulnerability in Fleet's MDM bootstrap...
CVE-2026-34385HIGH8.1Fleet is open source device management software. Prior to 4.81.0, a second-order SQL injection vulnerability in Fleet's ...
CVE-2026-34375HIGH8.2WWBN AVideo is an open source video platform. In versions up to and including 26.0, the YPTWallet Stripe payment confirm...
CVE-2026-29180HIGH8.8Fleet is open source device management software. Prior to 4.81.1, a broken access control vulnerability in Fleet's host ...
CVE-2026-26061HIGH7.5Fleet is open source device management software. Prior to 4.81.0, Fleet contained multiple unauthenticated HTTP endpoint...
CVE-2026-26060HIGH8.8Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic c...
CVE-2026-4962HIGH7A security flaw has been discovered in UltraVNC up to 1.6.4.0. Affected by this issue is some unknown functionality in t...
CVE-2026-4961HIGH8.8A vulnerability was identified in Tenda AC6 15.03.05.16. Affected by this vulnerability is the function formQuickIndex o...
CVE-2026-4960HIGH8.8A vulnerability was determined in Tenda AC6 15.03.05.16. Affected is the function fromWizardHandle of the file /goform/W...
CVE-2026-33867HIGH7.5WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows content owners to pass...
CVE-2026-33767HIGH8.8WWBN AVideo is an open source video platform. In versions up to and including 26.0, in `objects/like.php`, the `getLike(...
CVE-2026-30576HIGH7.5A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file...
CVE-2026-30575HIGH7.5A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file...
CVE-2026-30574HIGH7.5A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file...
CVE-2026-4959HIGH7.5A vulnerability was found in OpenBMB XAgent 1.0.0. This impacts the function check_user of the file XAgentServer/applica...
CVE-2026-32983HIGH7.5Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-i...
CVE-2026-30534HIGH8.3A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/manage_category.php via...
CVE-2026-30531HIGH8.8A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifi...
CVE-2026-30529HIGH8.8A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifi...
CVE-2026-5027HIGH8.8The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an a...
CVE-2026-4984HIGH8.2The Twilio integration webhook handler accepts any POST request without validating Twilio's 'X-Twilio-Signature'. When ...
CVE-2026-4956HIGH7.3A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. The affected element is an unknown f...
CVE-2026-4955HIGH7.3A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. This impacts an unknown function of the...
CVE-2026-4953HIGH7.3A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/...
CVE-2026-33757HIGH8.3OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now