2026 CVE Vulnerabilities

56,373 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-1111HIGH7.2A vulnerability has been found in Sanluan PublicCMS up to 5.202506.d. This impacts the function Save of the file com/pub...
CVE-2026-1110HIGH7.8A flaw has been found in cijliu librtsp up to 2ec1a81ad65280568a0c7c16420d7c10fde13b04. This affects the function rtsp_p...
CVE-2026-1109HIGH7.8A vulnerability was detected in cijliu librtsp up to 2ec1a81ad65280568a0c7c16420d7c10fde13b04. The impacted element is t...
CVE-2026-1108HIGH7.8A security vulnerability has been detected in cijliu librtsp up to 2ec1a81ad65280568a0c7c16420d7c10fde13b04. The affecte...
CVE-2026-1066HIGH8.8A vulnerability was detected in kalcaddle kodbox up to 1.61.10. This issue affects some unknown processing of the file /...
CVE-2026-1050HIGH7.3A flaw has been found in risesoft-y9 Digital-Infrastructure up to 9.6.7. This affects an unknown function of the file so...
CVE-2026-0517HIGH7.5CVE-2026-0517 is a denial-of-service vulnerability in versions of Secure Access Server prior to 14.20. An attacker can ...
CVE-2026-22865HIGH7.4Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving d...
CVE-2026-22816HIGH7.4Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving d...
CVE-2026-21223HIGH7.1Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feat...
CVE-2026-20960HIGH8Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.
CVE-2026-23742HIGH8.8Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was...
CVE-2026-23735HIGH8.7GraphQL Modules is a toolset of libraries and guidelines dedicated to create reusable, maintainable, testable and extend...
CVE-2026-23723HIGH7.2WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an authenticated SQL Injection vulnerability was ide...
CVE-2026-23535HIGH8wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could wri...
CVE-2026-23490HIGH7.5pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to mem...
CVE-2026-0629HIGH8.7Authentication bypass in the password recovery feature of the local web interface across multiple VIGI camera models all...
CVE-2026-23529HIGH7.7Kafka Connect BigQuery Connector is an implementation of a sink connector from Apache Kafka to Google BigQuery. Prior to...
CVE-2026-23523HIGH8.8Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. Prior to 0.13.0...
CVE-2026-22782HIGH7.5RustFS is a distributed object storage system built in Rust. From >= 1.0.0-alpha.1 to 1.0.0-alpha.79, invalid RPC signat...
CVE-2026-21625HIGH8.8User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by ...
CVE-2026-0616HIGH7.5TheLibrarians web_fetch tool can be used to retrieve the Adminer interface content, which can then be used to log into t...
CVE-2026-0615HIGH7.3The Librarian `supervisord` status page can be retrieved by the `web_fetch` tool, which can be used to retrieve running ...
CVE-2026-0613HIGH7.5The Librarian contains an internal port scanning vulnerability, facilitated by the `web_fetch` tool, which can be used w...
CVE-2026-0612HIGH7.5The Librarian contains a information leakage vulnerability through the `web_fetch` tool, which can be used to retrieve a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now