2026 CVE Vulnerabilities

56,936 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-53421CRITICAL9.8Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlemen...
CVE-2026-53405CRITICAL9.8Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements...
CVE-2026-52349HIGH7.8Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local a...
CVE-2026-51386Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2026-46409. Reason: This record is a reservation duplicate ...
CVE-2026-46516MEDIUM4.8Frogman provides headless FreePBX control. Prior to version 1.6.6, Frogman's chat-console markdown formatter (`assets/js...
CVE-2026-46410HIGH8.7FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable and 1.4.1-beta may le...
CVE-2026-45270HIGH8.7CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module...
CVE-2026-45139MEDIUM6.5CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enfo...
CVE-2026-16277MEDIUM6.5A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcin...
CVE-2026-16252HIGH7.3A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System ...
CVE-2026-12701CRITICAL9A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content pa...
CVE-2026-57311MEDIUM5.3Windu CMS does not validate types of uploaded files. An authenticated attacker can upload arbitrary files, including PHP...
CVE-2026-57310MEDIUM6.3Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an attacker...
CVE-2026-57309CRITICAL9.3A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to injec...
CVE-2026-16248HIGH8.8A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the ...
CVE-2026-16244MEDIUM6.3A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected by this vulnerabilit...
CVE-2026-12080HIGH7.3A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-a...
CVE-2026-64623HIGH8.8Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the...
CVE-2026-64622CRITICAL9.3Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/...
CVE-2026-64621CRITICAL9.3FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_appl...
CVE-2026-64620CRITICAL9.1FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypt...
CVE-2026-63763HIGH8.8SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileg...
CVE-2026-63762MEDIUM6.5SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded JavaScript...
CVE-2026-63761MEDIUM5.3SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is configured with ALGORITHM ES...
CVE-2026-63760HIGH8.7SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processin...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now