2026 CVE Vulnerabilities

56,998 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15685HIGH7.5Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote...
CVE-2026-15684HIGH7.3Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attac...
CVE-2026-15683HIGH7.5Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability. This vulne...
CVE-2026-15682MEDIUM5.5AnyDesk Support Information Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to...
CVE-2026-15681MEDIUM5.5AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to cr...
CVE-2026-15680HIGH7.5Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability. This vulnerabil...
CVE-2026-15598MEDIUM6.3A weakness has been identified in antv layout 2.0.0. This impacts the function setNestedValue in the library lib/util/ob...
CVE-2026-15597HIGH7.3A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/2.php. This affects an unkno...
CVE-2026-15596MEDIUM4.3A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unkno...
CVE-2026-58410HIGH7.1ChurchCRM is an open-source church management system. Prior to version 7.4.0, there was an authorization flaw in the fam...
CVE-2026-58409CRITICAL9.1ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated administrator can achieve...
CVE-2026-48364HIGH8.2ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that c...
CVE-2026-48363HIGH8.2ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that c...
CVE-2026-15595MEDIUM4.3A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unkno...
CVE-2026-15594LOW3.7A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the l...
CVE-2026-58408MEDIUM6.5ChurchCRM is an open-source church management system. Prior to version 7.4.0, a low-privileged user can bypass the /admi...
CVE-2026-58407Rejected reason: Please submit CVE requests for each vulnerability.
CVE-2026-55773HIGH8.8CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisi...
CVE-2026-55771HIGH8.8CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisi...
CVE-2026-12536MEDIUM6.4The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Module Title’ para...
CVE-2026-12385MEDIUM4.3The Smart Slider 3 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu...
CVE-2026-6875CRITICAL9.5ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This v...
CVE-2026-58228MEDIUM5.1Cross-site scripting vulnerability in phoenixframework phoenix_live_view allows an attacker to bypass URL scheme validat...
CVE-2026-55772HIGH8.8CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisi...
CVE-2026-49972HIGH8.8Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows unauthenticated attackers to achieve remo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now