2026 CVE Vulnerabilities

59,295 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-58521CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foun...
CVE-2026-58520MEDIUM6.1URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener E...
CVE-2026-57737MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortco...
CVE-2026-57736HIGH7.4Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. Thi...
CVE-2026-57723HIGH7.4Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal....
CVE-2026-57722MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable ...
CVE-2026-54428HIGH7.5Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 an...
CVE-2026-51946MEDIUM6.5SQL Injection vulnerability in GoAdminGroup GoAdmin (last release v1.2.26) allows a remote attacker to execute arbitrary...
CVE-2026-49091HIGH8Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forgin...
CVE-2026-49090MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (C...
CVE-2026-46680HIGH7.8containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched...
CVE-2026-58454HIGH7.7JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a remote code execution vulnerability that ...
CVE-2026-58453CRITICAL9.8JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that...
CVE-2026-58452HIGH8.8JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain an OS command injection vulnerability that ...
CVE-2026-57721MEDIUM5.3Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control S...
CVE-2026-57720MEDIUM4.3Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control ...
CVE-2026-57516HIGH8.8Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to a...
CVE-2026-56152MEDIUM5.3Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality ...
CVE-2026-56151MEDIUM6.5Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An...
CVE-2026-56150HIGH7.5Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Exces...
CVE-2026-56149MEDIUM4.9Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce...
CVE-2026-56148MEDIUM6.5Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). ...
CVE-2026-54399HIGH7.5Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and ...
CVE-2026-49088MEDIUM4.4Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclosure. When the option...
CVE-2026-49087MEDIUM6.5Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now