2026 CVE Vulnerabilities

43,970 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-19211HIGH7.3A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file /socia...
CVE-2026-17603HIGH8.7Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the Data...
CVE-2026-17601HIGH8.9A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their ...
CVE-2026-17600HIGH8.7Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissio...
CVE-2026-17599MEDIUM6.9Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. Th...
CVE-2026-17598MEDIUM5.3Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when ...
CVE-2026-17597MEDIUM5.1Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification f...
CVE-2026-17596MEDIUM6.3Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:cre...
CVE-2026-17595MEDIUM5.3Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:select...
CVE-2026-17594HIGH8.2Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in th...
CVE-2026-17593HIGH7.2An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permissi...
CVE-2026-14644HIGH8.6Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with...
CVE-2026-66059MEDIUM5.3Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass expose...
CVE-2026-62996MEDIUM6.9Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From...
CVE-2026-62992MEDIUM6.9Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prio...
CVE-2026-48093MEDIUM6.5The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting (XSS) through the ex...
CVE-2026-19210MEDIUM6.3A vulnerability has been found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of...
CVE-2026-19209LOW3.5A flaw has been found in SourceCodester Photo Share Website 1.0. The affected element is an unknown function of the file...
CVE-2026-19208LOW3.7A vulnerability was detected in WonderTrader up to 0.9.9. Impacted is the function TraderDD::queryTrades of the file src...
CVE-2026-19264CRITICAL9.8Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied pat...
CVE-2026-19207LOW2.4A security vulnerability has been detected in PHPGurukul Company Visitor Management System 1.0. This issue affects some ...
CVE-2026-18497HIGH7.1A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for p...
CVE-2026-66914CRITICAL9.2Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated...
CVE-2026-61477LOW2.3An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline ...
CVE-2026-37171MEDIUM5.9A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now