2026 CVE Vulnerabilities

64,909 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-90770HIGH8.8Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supp...
CVE-2026-90769HIGH7.7Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated us...
CVE-2026-90768HIGH8.1CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to re...
CVE-2026-90562HIGH8.1LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the...
CVE-2026-90561HIGH8.7Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the cont...
CVE-2026-90514HIGH7.3A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function...
CVE-2026-90510HIGH8.3A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceI...
CVE-2026-90509HIGH7.3A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspec...
CVE-2026-90504HIGH7.3A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted e...
CVE-2026-90498HIGH7.3A vulnerability was identified in lenve vhr 1.0-SNAPSHOT. Affected by this issue is some unknown functionality of the fi...
CVE-2026-89080HIGH7.5The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an ...
CVE-2026-86406HIGH7.5The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a mem...
CVE-2026-80071HIGH7.2The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership...
CVE-2026-90678HIGH7.5An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3...
CVE-2026-90495HIGH7.3A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance-...
CVE-2026-90493HIGH8.8A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is ...
CVE-2026-90668HIGH7.5The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which al...
CVE-2026-90651HIGH8.1Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certific...
CVE-2026-90648HIGH7.1wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platfor...
CVE-2026-90647HIGH7.4ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation...
CVE-2026-90616HIGH7.4In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, whi...
CVE-2026-90560HIGH8.2zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress construct...
CVE-2026-90559HIGH7.5snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) ...
CVE-2026-90556HIGH7.8Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with decl...
CVE-2026-90554HIGH7.5vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when extracting audio from video...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now