2026 CVE Vulnerabilities

53,401 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-33717HIGH8.8WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `downloadVideoFromDownloadURL()`...
CVE-2026-33681HIGH7.2WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginRunDatabaseScript...
CVE-2026-33651HIGH8.8WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `remindMe.json.php` endpoint pas...
CVE-2026-33650HIGH7.6WWBN AVideo is an open source video platform. In versions up to and including 26.0, a user with the "Videos Moderator" p...
CVE-2026-33649HIGH8.8WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Permissions/setPermissio...
CVE-2026-33648HIGH8.8WWBN AVideo is an open source video platform. In versions up to and including 26.0, the restreamer endpoint constructs a...
CVE-2026-33647HIGH8.8WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `ImageGallery::saveFile()` metho...
CVE-2026-33513HIGH7.5WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated API endpoint (`AP...
CVE-2026-33512HIGH7.5WWBN AVideo is an open source video platform. In versions up to and including 26.0, the API plugin exposes a `decryptStr...
CVE-2026-26209HIGH7.5cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format. Versions ...
CVE-2026-25075HIGH8.7strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allo...
CVE-2026-4594HIGH7.3A vulnerability has been found in erupts erupt up to 1.13.3. Affected by this issue is the function geneEruptHqlOrderBy ...
CVE-2026-33507HIGH8.8WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginImport.json.php` ...
CVE-2026-33502HIGH8.2WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side reque...
CVE-2026-26829HIGH7.5A NULL pointer dereference in the safe_atou64 function (src/misc.c) of owntone-server through commit c4d57aa allows atta...
CVE-2026-26828HIGH7.5A NULL pointer dereference in the daap_reply_playlists function (src/httpd_daap.c) of owntone-server commit 3d1652d allo...
CVE-2026-24516HIGH8.8A command injection vulnerability exists in DigitalOcean Droplet Agent through 1.3.2. The troubleshooting actioner compo...
CVE-2026-33493HIGH8.1WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/import.json.php` endpoi...
CVE-2026-33492HIGH7.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo's `_session_start()` function...
CVE-2026-33488HIGH8.1WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `createKeys()` function in the L...
CVE-2026-32845HIGH8.4cgltf version 1.15 and prior contain an integer overflow vulnerability in the cgltf_validate() function when validating ...
CVE-2026-33485HIGH7.5WWBN AVideo is an open source video platform. In versions up to and including 26.0, the RTMP `on_publish` callback at `p...
CVE-2026-33483HIGH7.5WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `aVideoEncoderChunk.json.php` en...
CVE-2026-33482HIGH8.1WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `sanitizeFFmpegCommand()` functi...
CVE-2026-33480HIGH8.6WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `isSSRFSafeURL()` function in AV...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now