2026 CVE Vulnerabilities

64,909 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-90929HIGH8.1File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (res...
CVE-2026-90715HIGH7.3A security vulnerability has been detected in marcobambini Gravity up to 0.9.7. This affects an unknown function of the ...
CVE-2026-78336HIGH7.5Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query f...
CVE-2026-73178HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope. An administrator with adequ...
CVE-2026-90710HIGH7.3A vulnerability was determined in taisan tarzan-cms 1.0.0. This issue affects the function openConnection of the file co...
CVE-2026-90708HIGH7.3A weakness has been identified in Yot CMS up to 3.3.1. Affected by this vulnerability is the function Login of the file ...
CVE-2026-90707HIGH8.3A security flaw has been discovered in Open5GS up to 2.7.x. Affected is the function amf_nnrf_try_old_amf_discovery_fall...
CVE-2026-8821HIGH7.1Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel m...
CVE-2026-89180HIGH7.5EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote atta...
CVE-2026-87779HIGH7.5Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of non-standard length...
CVE-2026-81564HIGH7Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP P...
CVE-2026-78375HIGH8.6Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Fre...
CVE-2026-20773HIGH8.5A role-based access control issue was identified in the administrative expression evaluation functionality. This could a...
CVE-2026-90895HIGH8.4Affected versions of MISP’s interactive CLI shell implement access control independently from the normal web application...
CVE-2026-90894HIGH7.8Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_s...
CVE-2026-90701HIGH7.3A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a...
CVE-2026-72524HIGH8.8Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access...
CVE-2026-12518HIGH8.5A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privile...
CVE-2026-90691HIGH8.3A security vulnerability has been detected in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The imp...
CVE-2026-90690HIGH7.3A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The affected elemen...
CVE-2026-90689HIGH8.8A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuth...
CVE-2026-88853HIGH7.5Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla <...
CVE-2026-88852HIGH7.5Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0,...
CVE-2026-85195HIGH7.5Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 2...
CVE-2026-85191HIGH7.5Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joom...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now