2026 CVE Vulnerabilities

57,011 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-14453CRITICAL9.6This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that l...
CVE-2026-10106MEDIUM6.5Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced i...
CVE-2026-10103MEDIUM4.3Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared ...
CVE-2026-10085MEDIUM5.4Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained chann...
CVE-2026-57830CRITICAL9.1Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla exten...
CVE-2026-57829MEDIUM6.1Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ul...
CVE-2026-4769CRITICAL9.8Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startu...
CVE-2026-15544HIGH8.8A vulnerability was determined in Shibby Tomato up to 1.28.0000. Affected is the function getupsvar of the file www/apcu...
CVE-2026-15543HIGH8.8A vulnerability was found in Tenda CH22 1.0.0.1. This impacts the function formCertListInfo of the file /goform/CertList...
CVE-2026-15542HIGH7.3A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of the file app/main.g...
CVE-2026-15541HIGH7.3A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file a...
CVE-2026-15540MEDIUM4.3A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function...
CVE-2026-14165HIGH7.5An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through ...
CVE-2026-15539MEDIUM4.7A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown functi...
CVE-2026-15538MEDIUM6.3A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the function ObjectUtils.mutate...
CVE-2026-15537HIGH7.3A security flaw has been discovered in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown c...
CVE-2026-15536MEDIUM6.3A vulnerability was identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file ...
CVE-2026-12582HIGH8.6The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter befor...
CVE-2026-12397MEDIUM4.3The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employer's contact email fo...
CVE-2026-12396MEDIUM5.4The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks before allowing job mod...
CVE-2026-12275HIGH7.1The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enr...
CVE-2026-12274MEDIUM6.5The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to edit a target post ...
CVE-2026-12273MEDIUM4.3The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target validation before creati...
CVE-2026-12271MEDIUM5.4The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt before writing to i...
CVE-2026-12081MEDIUM5The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not restrict the PHP classe...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now