2026 CVE Vulnerabilities

55,811 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-25711HIGH7.5The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to...
CVE-2026-20895HIGH7.5The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to...
CVE-2026-20791HIGH7.5Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-1585HIGH8.4An unquoted Windows service executable path vulnerability in IJ Scan Utility for Windows versions 1.1.2 through 1.5.0 ma...
CVE-2026-3265HIGH8.8A vulnerability was identified in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. This affects an unk...
CVE-2026-3264HIGH8.8A vulnerability was determined in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. Affected by this is...
CVE-2026-28280HIGH8.7osctrl is an osquery management solution. Prior to version 0.5.0, a stored cross-site scripting (XSS) vulnerability exis...
CVE-2026-28279HIGH8.4osctrl is an osquery management solution. Prior to version 0.5.0, an OS command injection vulnerability exists in the `o...
CVE-2026-28276HIGH7.5Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions p...
CVE-2026-28275HIGH8.1Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 do not invalidate p...
CVE-2026-28274HIGH8.7Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to S...
CVE-2026-28269HIGH8.8Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functio...
CVE-2026-28216HIGH8.3hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify o...
CVE-2026-28211HIGH7.8The NVDA Dev & Test Toolbox is an NVDA add-on for gathering tools to help NVDA development and testing. A vulnerability ...
CVE-2026-28207HIGH7.3Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.2, a command inj...
CVE-2026-27638HIGH7.1Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), the sync API endpoi...
CVE-2026-3263HIGH8.8A vulnerability was found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected by this...
CVE-2026-3262HIGH8.8A vulnerability has been found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected is...
CVE-2026-27449HIGH7.5Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versi...
CVE-2026-25741HIGH7.1Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpo...
CVE-2026-22206HIGH8.8SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to exe...
CVE-2026-22205HIGH8.7SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows una...
CVE-2026-27510HIGH8.8Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.dogg...
CVE-2026-27509HIGH8.5Unitree Go2 firmware versions V1.1.7 through V1.1.9, and V1.1.11 (EDU) do not implement DDS authentication or authorizat...
CVE-2026-27141HIGH7.5Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now