2026 CVE Vulnerabilities

59,898 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41052HIGH8.8Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2...
CVE-2026-13750MEDIUM5.5Insertion of sensitive information into log files in Snowflake CLI versions prior to 3.19 allowed plaintext credentials ...
CVE-2026-13749HIGH8.8Improper neutralization in the Snowpark annotation processor callback template in Snowflake CLI versions prior to 3.19 a...
CVE-2026-13748MEDIUM6.3Improper restriction of file path resolution in Snowflake CLI versions prior to 3.19 allowed arbitrary local file conten...
CVE-2026-13746MEDIUM5.4Improper neutralization of local CLI parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution...
CVE-2026-13744HIGH8.8Improper neutralization of attacker-controlled content in Snowflake CLI versions prior to 3.19 allowed unintended SQL ex...
CVE-2026-13742MEDIUM5.9Honeywell IQ MultiAccess, all versions prior to and including version 28, contain an improper digital signature verifica...
CVE-2026-13587LOW3.7A vulnerability was found in seladb PcapPlusPlus 25.05. The affected element is the function parse_by_block_type of the ...
CVE-2026-13583HIGH8.8A vulnerability has been found in Edimax EW-7478APC 1.04. Impacted is the function formUSBFolder of the file /goform/for...
CVE-2026-13582HIGH8.8A flaw has been found in Edimax EW-7478APC 1.04. This issue affects the function formUSBAccount of the file /goform/form...
CVE-2026-13581MEDIUM6.3A vulnerability was detected in Edimax EW-7478APC 1.04. This vulnerability affects the function formStaDrvSetup of the f...
CVE-2026-13580HIGH8.8A security vulnerability has been detected in Edimax EW-7478APC 1.04. This affects the function formQoS of the file /gof...
CVE-2026-13437MEDIUM6.5Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 a...
CVE-2026-57525Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-57523Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-57341MEDIUM6.5Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce ...
CVE-2026-57340MEDIUM6.5Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.
CVE-2026-57339MEDIUM6.5Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.
CVE-2026-57338HIGH7.1Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions.
CVE-2026-57337HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions.
CVE-2026-57336HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Jobify <= 4.3.2 versions.
CVE-2026-57335MEDIUM6.5Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions.
CVE-2026-57334MEDIUM6.5Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.
CVE-2026-57333HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free <= 0.9.4 versions.
CVE-2026-57332HIGH7.1Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now