2026 CVE Vulnerabilities

55,833 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-27615HIGH7.8ADB Explorer is a fluent UI for ADB on Windows. In versions prior to Beta 0.9.26022, ADB-Explorer allows the `ManualAdbP...
CVE-2026-27608HIGH8.1Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha...
CVE-2026-27595HIGH7.5Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha...
CVE-2026-2914HIGH7.8CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation le...
CVE-2026-25131HIGH8.8OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio...
CVE-2026-3137HIGH7.8A security vulnerability has been detected in CodeAstro Food Ordering System 1.0. This affects an unknown function of th...
CVE-2026-27593HIGH8.8Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker...
CVE-2026-27572HIGH7.5Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implemen...
CVE-2026-27195HIGH7.5Wasmtime is a runtime for WebAssembly. Starting with Wasmtime 39.0.0, the `component-model-async` feature became the def...
CVE-2026-27117HIGH7.5bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4...
CVE-2026-25899HIGH7.5Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `f...
CVE-2026-25891HIGH7.5Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remo...
CVE-2026-25882HIGH7.5Fiber is an Express inspired web framework written in Go. A denial of service vulnerability exists in Fiber v2 and v3 th...
CVE-2026-24443HIGH8.8EventSentry versions prior to 6.0.1.20 contain an unverified password change vulnerability in the account management fun...
CVE-2026-3105HIGH8.8SummaryThis advisory addresses a SQL injection vulnerability in the API endpoint used for retrieving contact activities....
CVE-2026-26340HIGH7.5Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior expose RTSP streams without requirin...
CVE-2026-24241HIGH7.5NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker could exploit ...
CVE-2026-22766HIGH7.2Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Unrestricted Upload of File with Dangerous Type vulner...
CVE-2026-22765HIGH8.8Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Missing Authorization vulnerability. A low privileged a...
CVE-2026-27468HIGH8.2Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval b...
CVE-2026-27571HIGH7.5NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The WebSockets handling ...
CVE-2026-27521HIGH7.5Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior do not implement rate limiting or accoun...
CVE-2026-27520HIGH8.7Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side c...
CVE-2026-27519HIGH8.7Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior use RC4 with a hard-coded key embedded i...
CVE-2026-27516HIGH8.6Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior expose user passwords in plaintext withi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now