2026 CVE Vulnerabilities

53,691 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-28679HIGH7.5Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. Prior to version 1.21.0,...
CVE-2026-28677HIGH8.2OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version...
CVE-2026-28676HIGH8.8OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version...
CVE-2026-28508HIGH8.6Idno is a social publishing platform. Prior to version 1.6.4, a logic error in the API authentication flow causes the CS...
CVE-2026-28507HIGH7.2Idno is a social publishing platform. Prior to version 1.6.4, there is a remote code execution vulnerability via chained...
CVE-2026-28429HIGH7.5Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871, a Path Traversal vulnerability was identified i...
CVE-2026-27603HIGH7.5Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-25888HIGH8.8Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-25887HIGH7.2Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-29046HIGH8.2TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header...
CVE-2026-29041HIGH8.8Chamilo is a learning management system. Prior to version 1.11.34, Chamilo LMS is affected by an authenticated remote co...
CVE-2026-28502HIGH8.8WWBN AVideo is an open source video platform. Prior to version 24.0, an authenticated Remote Code Execution (RCE) vulner...
CVE-2026-3613HIGH7.3A vulnerability was identified in Wavlink WL-NU516U1 V240425. This vulnerability affects the function sub_401A0C of the ...
CVE-2026-3612HIGH7.3A vulnerability was determined in Wavlink WL-NU516U1 V240425. This affects the function sub_405AF4 of the file /cgi-bin/...
CVE-2026-28727HIGH7.8Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber P...
CVE-2026-28722HIGH7.3Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec...
CVE-2026-28721HIGH7.3Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec...
CVE-2026-28718HIGH7.5Denial of service due to insufficient input validation in authentication logging. The following products are affected: A...
CVE-2026-28713HIGH7.1Default credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyb...
CVE-2026-27778HIGH8.7The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc...
CVE-2026-24912HIGH8.6The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ...
CVE-2026-29613HIGH8.2OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in whi...
CVE-2026-29612HIGH7.5OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget...
CVE-2026-29611HIGH8.2OpenClaw versions prior to 2026.2.14 contain a local file inclusion vulnerability in BlueBubbles extension (must be inst...
CVE-2026-29610HIGH8.8OpenClaw versions prior to 2026.2.14 contain a command hijacking vulnerability that allows attackers to execute unintend...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now