2026 CVE Vulnerabilities

57,111 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-46463MEDIUM6.5Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-59234MEDIUM6.9Authorization Bypass Through User-Controlled Key (CWE-639) in CalendarDeleteEventController (app/Http/Controllers/Calend...
CVE-2026-56085LOW3.3Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-56015CRITICAL9.1Net::IP::LPM versions before 1.11 for Perl allow a heap out-of-bounds read via an unbounded prefix length. add() passes...
CVE-2026-54483MEDIUM6.7Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-46730MEDIUM4.2Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-46468MEDIUM4.4Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-46467MEDIUM5.8Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-44269MEDIUM4.4Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-44268MEDIUM4.4Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-41124MEDIUM4.4Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-41123MEDIUM4.3Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-26355MEDIUM6.5Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-50238Rejected reason: Red Hat Product Security has concluded that this CVE is not required. The reported issue has been class...
CVE-2026-13341HIGH7.4A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow...
CVE-2026-10055HIGH8.5In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from...
CVE-2026-10054HIGH8.8In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSoc...
CVE-2026-5137MEDIUM4.3The RTMKit (rometheme-for-elementor) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and i...
CVE-2026-4322MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Raera - Ankara Web...
CVE-2026-4321CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web...
CVE-2026-9756MEDIUM6.4The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldTy...
CVE-2026-4804MEDIUM6.4The Zakra theme for WordPress is vulnerable to Stored Cross-Site Scripting via post meta values in all versions up to, a...
CVE-2026-47896HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucen...
CVE-2026-35159MEDIUM5.3Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attack...
CVE-2026-11900MEDIUM4.3The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Insecure Direct Object Reference in ver...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now