2026 CVE Vulnerabilities

56,258 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-25495HIGH8.8Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through ...
CVE-2026-25231HIGH7.5FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 3.3.0, the application contains an unauthe...
CVE-2026-1529HIGH8.1A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target ema...
CVE-2026-1486HIGH8.8A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verif...
CVE-2026-24684HIGH7.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can p...
CVE-2026-24683HIGH7.5FreeRDP is a free implementation of the Remote Desktop Protocol. ainput_send_input_event caches channel_callback in a lo...
CVE-2026-24682HIGH7.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, audin_server_recv_formats frees an inc...
CVE-2026-24681HIGH7.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, aAsynchronous bulk transfer completion...
CVE-2026-24680HIGH7.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, sdl_Pointer_New frees data on failure,...
CVE-2026-24678HIGH7.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, A capture thread sends sample response...
CVE-2026-24676HIGH7.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, AUDIN format renegotiation frees the a...
CVE-2026-24675HIGH7.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, urb_select_interface can free the devi...
CVE-2026-24491HIGH7.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, video_timer can send client notificati...
CVE-2026-23948HIGH7.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, a NULL pointer dereference vulnerabili...
CVE-2026-2227HIGH7.2A vulnerability was found in D-Link DCS-931L up to 1.13.0. Impacted is the function doSystem of the file /setSystemAdmin...
CVE-2026-2226HIGH7.2A vulnerability has been found in DouPHP up to 1.9. This issue affects some unknown processing of the file /admin/file.p...
CVE-2026-2236HIGH8.7C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbit...
CVE-2026-2235HIGH7.1C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrar...
CVE-2026-22905HIGH7.5An unauthenticated remote attacker can bypass authentication by exploiting insufficient URI validation and using path tr...
CVE-2026-24466HIGH8.4Products provided by Oki Electric Industry Co., Ltd. and its OEM products (Ricoh Co., Ltd., Murata Machinery, Ltd.) regi...
CVE-2026-0870HIGH8.5MacroHub developed by GIGABYTE has a Local Privilege Escalation vulnerability. Due to the MacroHub application launching...
CVE-2026-2218HIGH8.8A vulnerability was determined in D-Link DCS-933L up to 1.14.11. This affects an unknown function of the file /setSystem...
CVE-2026-2213HIGH7.2A security flaw has been discovered in code-projects Online Music Site 1.0. Affected by this issue is some unknown funct...
CVE-2026-2210HIGH7.3A vulnerability has been found in D-Link DIR-823X 250416. This affects the function sub_4211C8 of the file /goform/set_f...
CVE-2026-2203HIGH8.8A flaw has been found in Tenda AC8 16.03.33.05. Affected by this vulnerability is an unknown functionality of the file /...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now