2026 CVE Vulnerabilities

65,828 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-88956MEDIUM6.8The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the ...
CVE-2026-88761MEDIUM5.3The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portion...
CVE-2026-85496HIGH8.8The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a ...
CVE-2026-84399HIGH8.8The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionalit...
CVE-2026-82566HIGH8.8The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can rem...
CVE-2026-82372HIGH8.5Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0....
CVE-2026-82164HIGH7.1Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resourc...
CVE-2026-77967HIGH8.1The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshnes...
CVE-2026-48543MEDIUM5.4Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attack...
CVE-2026-48542MEDIUM5.4Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attack...
CVE-2026-48541MEDIUM5.4Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attack...
CVE-2026-48540MEDIUM5.4Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attack...
CVE-2026-97323MEDIUM6.3A vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This impacts the function getOrigina...
CVE-2026-97322MEDIUM4.3A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the f...
CVE-2026-97321MEDIUM6.3A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The impacted element is the function...
CVE-2026-97320MEDIUM6.3A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The affected element is the function AiKnowle...
CVE-2026-96749HIGH8.4An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may ...
CVE-2026-96748MEDIUM6.5PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separ...
CVE-2026-96747MEDIUM5The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value en...
CVE-2026-89325HIGH7.8An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, l...
CVE-2026-86860CRITICAL9.3ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This ...
CVE-2026-86859HIGH8.7ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This...
CVE-2026-86858HIGH8.7ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. T...
CVE-2026-86857HIGH8.4ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This...
CVE-2026-85738MEDIUM6.3TREK is a collaborative travel planner. Prior to 3.4.0, the checkSsrf logic in server/src/utils/ssrfGuard.ts does not re...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now