2026 CVE Vulnerabilities

56,336 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-1117HIGH8.2A vulnerability in the `lollms_generation_events.py` component of parisneo/lollms version 5.9.0 allows unauthenticated a...
CVE-2026-20412HIGH7.8In cameraisp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation...
CVE-2026-20411HIGH7.8In cameraisp, there is a possible escalation of privilege due to use after free. This could lead to local denial of serv...
CVE-2026-20409HIGH7.8In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of...
CVE-2026-20408HIGH8.8In wlan, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adja...
CVE-2026-20401HIGH7.5In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if...
CVE-2026-22888HIGH7.5Improper input verification issue exists in Cybozu Garoon 5.0.0 to 6.0.3, which may lead to unauthorized alteration of p...
CVE-2026-1746HIGH8.8A vulnerability was identified in JeecgBoot 3.9.0. This vulnerability affects unknown code of the file /JeecgBoot/sys/ap...
CVE-2026-1531HIGH8.1A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification...
CVE-2026-1530HIGH8.1A flaw was found in fog-kubevirt. This vulnerability allows a remote attacker to perform a Man-in-the-Middle (MITM) atta...
CVE-2026-25201HIGH8.8An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9...
CVE-2026-24788HIGH8.8RaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary O...
CVE-2026-1742HIGH7.2A vulnerability was identified in EFM ipTIME A8004T 14.18.2. Affected by this vulnerability is the function commit_vpncl...
CVE-2026-1739HIGH7.5A vulnerability has been found in Free5GC pcf up to 1.4.1. This affects the function HandleCreateSmPolicyRequest of the ...
CVE-2026-25253HIGH8.8OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically mak...
CVE-2026-23025HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: prevent pcp corruption with SMP=n T...
CVE-2026-25153HIGH8.8Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node....
CVE-2026-25129HIGH7.3PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Prior to versions 0.11.23 and 0.12.19, Psy...
CVE-2026-1702HIGH8.8A vulnerability was detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknown function of ...
CVE-2026-1691HIGH8.8A vulnerability has been found in bolo-solo up to 2.6.4. This impacts the function importMarkdownsSync of the file src/m...
CVE-2026-1689HIGH7.3A vulnerability was detected in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. The impacted element is the function che...
CVE-2026-25128HIGH7.5fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based li...
CVE-2026-24854HIGH8.8ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in endpoint `/PaddleNumEditor...
CVE-2026-1687HIGH7.3A weakness has been identified in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. Impacted is an unknown function of the...
CVE-2026-1686HIGH8.8A security flaw has been discovered in Totolink A3600R 5.9c.4959. This issue affects the function setAppEasyWizardConfig...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now