2026 CVE Vulnerabilities

57,015 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-12761CRITICAL9.8The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to auth...
CVE-2026-57850HIGH8.7RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a l...
CVE-2026-57158CRITICAL9.1FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GF...
CVE-2026-57157MEDIUM6.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, FreeRDP server implementations with th...
CVE-2026-57156CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients conta...
CVE-2026-55827HIGH8.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.1, FreeRDP clients launched with the non-...
CVE-2026-55789HIGH8.5Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML app...
CVE-2026-55515MEDIUM5Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authoriz...
CVE-2026-55481MEDIUM4.8Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related br...
CVE-2026-55479MEDIUM4.3Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorize...
CVE-2026-55475MEDIUM5.7Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV impo...
CVE-2026-55469MEDIUM6.5Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update p...
CVE-2026-55466HIGH8.7Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP...
CVE-2026-55462MEDIUM4.3Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authoriz...
CVE-2026-55461MEDIUM6.1Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the user edit flow stores url()->previous() from the ...
CVE-2026-55452HIGH7.3Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent ...
CVE-2026-55377HIGH8.1Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's Account Center step-...
CVE-2026-55370MEDIUM6.4Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's existing TOTP verifi...
CVE-2026-54714MEDIUM6.1Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, @logto/core reflected the SA...
CVE-2026-15295MEDIUM4.4The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm...
CVE-2026-11321HIGH7.1The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates user-supplied CSV field values directly into SQL ...
CVE-2026-6872Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-6212HIGH8.8Authorization bypass through User-Controlled key vulnerability in Teracity Software Technologies Inc. TeraMIS allows Pri...
CVE-2026-61461HIGH8.8Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers ...
CVE-2026-61460HIGH8.8Krayin CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadController, PersonController,...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now