2026 CVE Vulnerabilities

56,866 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-0500HIGH8.8Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthe...
CVE-2026-0498HIGH7.2SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the fu...
CVE-2026-0492HIGH8.8SAP HANA database is vulnerable to privilege escalation allowing an attacker with valid credentials of any user to switc...
CVE-2026-22812HIGH8.8OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP serv...
CVE-2026-22805HIGH8.6Metabase is an open-source data analytics platform. Prior to 55.13, 56.3, and 57.1, self-hosted Metabase instances that ...
CVE-2026-22801HIGH7.8LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ...
CVE-2026-22695HIGH7.1LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ...
CVE-2026-22799HIGH8.8Emlog is an open source website building system. emlog v2.6.1 and earlier exposes a REST API endpoint (/index.php?rest-a...
CVE-2026-22794HIGH8.8Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the server uses the Origin ...
CVE-2026-22789HIGH8.8WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, WebErpMesv2 con...
CVE-2026-22788HIGH8.2WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, the WebErpMesV2...
CVE-2026-22786HIGH7.2Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-admin <= v2.8.7 has a path traversal vulner...
CVE-2026-22783HIGH8.1Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior...
CVE-2026-22776HIGH7.5cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.30.1, a Denial of S...
CVE-2026-22771HIGH8.8Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway...
CVE-2026-22200HIGH7.5Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerabi...
CVE-2026-0855HIGH8.8Certain IP Camera models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remot...
CVE-2026-0854HIGH8.8Certain DVR/NVR models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote ...
CVE-2026-0850HIGH7.2A vulnerability was determined in code-projects Intern Membership Management System 1.0. Impacted is an unknown function...
CVE-2026-0841HIGH8.8A vulnerability was detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /gof...
CVE-2026-0840HIGH8.8A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Affected by this vulnerability is the function s...
CVE-2026-0839HIGH8.8A weakness has been identified in UTT 进取 520W 1.7.7-180627. Affected is the function strcpy of the file /goform/APSecuri...
CVE-2026-0838HIGH8.8A security flaw has been discovered in UTT 进取 520W 1.7.7-180627. This impacts the function strcpy of the file /goform/Co...
CVE-2026-0837HIGH8.8A vulnerability was identified in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formFir...
CVE-2026-0836HIGH8.8A vulnerability was determined in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /gof...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now