2026 CVE Vulnerabilities

56,974 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-63175HIGH7.1PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level variables rather than in...
CVE-2026-62314MEDIUM5.8Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scrap...
CVE-2026-55652CRITICAL9.8Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequest...
CVE-2026-55576HIGH8.8MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/r...
CVE-2026-55445CRITICAL9.3Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript. Prior to 2.20.1, the...
CVE-2026-55234HIGH8.5Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.j...
CVE-2026-54458CRITICAL9.6WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerabi...
CVE-2026-53447MEDIUM6.5Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js use...
CVE-2026-53446MEDIUM6.2Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan webhook integration URLs in models/integrations.js a...
CVE-2026-53445HIGH7.1Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan copyBoard Meteor DDP method in server/publicatio...
CVE-2026-53444HIGH7.6Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan OIDC-related Meteor methods in packages/wekan-oidc/o...
CVE-2026-52893CRITICAL9.2Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook in server/models/user...
CVE-2026-52892MEDIUM6.5Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan REST handlers in server/models/customFields.js use r...
CVE-2026-52891CRITICAL9.9Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied fil...
CVE-2026-52890HIGH7.1Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachm...
CVE-2026-50183MEDIUM4.7WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerabilit...
CVE-2026-50182MEDIUM6.1WWBN AVideo is an open source video platform. Versions prior to 29.0 contain an unauthenticated Reflected XSS vulnerabil...
CVE-2026-49279HIGH7.7WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the aut...
CVE-2026-48795HIGH8.6AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompl...
CVE-2026-45313HIGH7.7Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegist...
CVE-2026-38974MEDIUM5.3Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py.
CVE-2026-38755LOW2.9A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Ser...
CVE-2026-38754MEDIUM5.1A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Serv...
CVE-2026-38752LOW2.9A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial ...
CVE-2026-36590HIGH7.5An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now