2026 CVE Vulnerabilities

66,216 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-78394MEDIUM4.1The Link Library WordPress plugin before 7.9.6 does not sanitize a user-supplied destination folder before writing a gen...
CVE-2026-78393MEDIUM6.1The Link Library WordPress plugin before 7.9.6 does not properly escape some parameters before outputting them in the ad...
CVE-2026-75553LOW2.4Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded cryptographic key, which may allow an att...
CVE-2026-62062HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This is...
CVE-2026-19775MEDIUM4.3The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress is vulnerable to authorizat...
CVE-2026-14281CRITICAL9.8The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulne...
CVE-2026-97721LOW2.7A weakness has been identified in Sanluan PublicCMS up to 6.202506.e. This vulnerability affects the function CmsContent...
CVE-2026-97818HIGH8.6phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.
CVE-2026-97764LOW3.7django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configu...
CVE-2026-97737HIGH7.4In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leadin...
CVE-2026-97736MEDIUM5.4tinyauth before 5.1.3 allows rule bypass by appending an allowed route string. This is caused by an unanchored regular e...
CVE-2026-97735HIGH8ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages ...
CVE-2026-97732MEDIUM5.1IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authenticates client executables by checking for exp...
CVE-2026-97731HIGH7.1MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied...
CVE-2026-97730HIGH8.5In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dash...
CVE-2026-97724MEDIUM4.3A prototype pollution vulnerability in Software Mansion React Native Worklets before 0.12.2 allows an attacker-controlle...
CVE-2026-97650MEDIUM4.3A vulnerability has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. A...
CVE-2026-97723MEDIUM5.4madpsy ka9q_ubersdr before 0.1.58 has a stored cross-site scripting (XSS) vulnerability in the chat message rendering fu...
CVE-2026-97649MEDIUM4.7A flaw has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected b...
CVE-2026-97648MEDIUM4.3A vulnerability was detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Aff...
CVE-2026-97647MEDIUM5.3A security vulnerability has been detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207c...
CVE-2026-95811MEDIUM6.5Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl...
CVE-2026-97646HIGH7.3A weakness has been identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. T...
CVE-2026-92289CRITICAL9.1Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKC...
CVE-2026-92288CRITICAL9.1Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now