2026 CVE Vulnerabilities
53,401 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33717 | HIGH | 8.8 | 0.4% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `downloadVideoFromDownloadURL()`... |
| CVE-2026-33681 | HIGH | 7.2 | 0.5% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginRunDatabaseScript... |
| CVE-2026-33651 | HIGH | 8.8 | 0.3% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `remindMe.json.php` endpoint pas... |
| CVE-2026-33650 | HIGH | 7.6 | 0.2% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, a user with the "Videos Moderator" p... |
| CVE-2026-33649 | HIGH | 8.8 | 0.2% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Permissions/setPermissio... |
| CVE-2026-33648 | HIGH | 8.8 | 0.6% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the restreamer endpoint constructs a... |
| CVE-2026-33647 | HIGH | 8.8 | 0.6% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `ImageGallery::saveFile()` metho... |
| CVE-2026-33513 | HIGH | 7.5 | 0.7% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated API endpoint (`AP... |
| CVE-2026-33512 | HIGH | 7.5 | 0.2% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the API plugin exposes a `decryptStr... |
| CVE-2026-26209 | HIGH | 7.5 | 0.4% | Mar 23, 2026 | cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format. Versions ... |
| CVE-2026-25075 | HIGH | 8.7 | 1.0% | Mar 23, 2026 | strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allo... |
| CVE-2026-4594 | HIGH | 7.3 | 0.3% | Mar 23, 2026 | A vulnerability has been found in erupts erupt up to 1.13.3. Affected by this issue is the function geneEruptHqlOrderBy ... |
| CVE-2026-33507 | HIGH | 8.8 | 0.4% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginImport.json.php` ... |
| CVE-2026-33502 | HIGH | 8.2 | 0.4% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side reque... |
| CVE-2026-26829 | HIGH | 7.5 | 0.9% | Mar 23, 2026 | A NULL pointer dereference in the safe_atou64 function (src/misc.c) of owntone-server through commit c4d57aa allows atta... |
| CVE-2026-26828 | HIGH | 7.5 | 0.3% | Mar 23, 2026 | A NULL pointer dereference in the daap_reply_playlists function (src/httpd_daap.c) of owntone-server commit 3d1652d allo... |
| CVE-2026-24516 | HIGH | 8.8 | 2.5% | Mar 23, 2026 | A command injection vulnerability exists in DigitalOcean Droplet Agent through 1.3.2. The troubleshooting actioner compo... |
| CVE-2026-33493 | HIGH | 8.1 | 0.3% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/import.json.php` endpoi... |
| CVE-2026-33492 | HIGH | 7.3 | 0.3% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo's `_session_start()` function... |
| CVE-2026-33488 | HIGH | 8.1 | 0.3% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `createKeys()` function in the L... |
| CVE-2026-32845 | HIGH | 8.4 | 0.1% | Mar 23, 2026 | cgltf version 1.15 and prior contain an integer overflow vulnerability in the cgltf_validate() function when validating ... |
| CVE-2026-33485 | HIGH | 7.5 | 0.5% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the RTMP `on_publish` callback at `p... |
| CVE-2026-33483 | HIGH | 7.5 | 0.6% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `aVideoEncoderChunk.json.php` en... |
| CVE-2026-33482 | HIGH | 8.1 | 2.1% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `sanitizeFFmpegCommand()` functi... |
| CVE-2026-33480 | HIGH | 8.6 | 0.3% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `isSSRFSafeURL()` function in AV... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now