2026 CVE Vulnerabilities

57,035 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56305HIGH8.7Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attack...
CVE-2026-56279HIGH8.7Capgo before 12.128.2 contains an information disclosure vulnerability in the get_orgs_v7(userid) RPC function that rema...
CVE-2026-56261HIGH7.5Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job ...
CVE-2026-56254HIGH8.3In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key...
CVE-2026-38059HIGH7.5The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated atta...
CVE-2026-38057HIGH8.1The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot en...
CVE-2026-29519HIGH8.2Lucee CFML Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x release lines contain a reflected cross-site script...
CVE-2026-22660HIGH8.6FlaskBB through 2.2.0, fixed in commit a5da9a5, contains a logic flaw vulnerability that allows authenticated administra...
CVE-2026-22659HIGH8.1FlaskBB through 2.2.0, fixed in commit acc88cf, contains an authorization bypass vulnerability that allows authenticated...
CVE-2026-56813LOW2.1Improper Neutralization of Parameter/Argument Delimiters vulnerability in elixir-plug plug allows an attacker to inject ...
CVE-2026-54470MEDIUM5.3Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Ref...
CVE-2026-54469HIGH8.8Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability...
CVE-2026-56814MEDIUM6.9Plug.Parsers.MULTIPART, the multipart request-body parser used to handle file uploads and multipart forms, does not enfo...
CVE-2026-56690HIGH8.5Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an S...
CVE-2026-56689HIGH7.7Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an S...
CVE-2026-56688CRITICAL9.1Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an O...
CVE-2026-54468MEDIUM6.5Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. A low privileged ...
CVE-2026-53363CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: preserve shared-frag marker in iptfs_c...
CVE-2026-58225LOW2.1SQL Injection vulnerability in elixir-ecto postgrex allows an attacker who can influence a LISTEN channel name to inject...
CVE-2026-14461MEDIUM5.1mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup() function. An attacker who can influence the TXT ...
CVE-2026-9857MEDIUM4.3The Invoice123 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.0. T...
CVE-2026-41880CRITICAL9R-SOFT DMS is vulnerable to OS Command Injection in the Optical Character Recognition (OCR) module. Multiple command exe...
CVE-2026-41879HIGH8.2R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password...
CVE-2026-41878HIGH7.1R-SOFT DMS is vulnerable to Insecure Direct Object Reference (IDOR) attack in multiple file download endpoints. The appl...
CVE-2026-41877MEDIUM5.1R-SOFT DMS is vulnerable to Stored XSS in file upload functionality. Authenticated attacker can inject arbitrary HTML an...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now