2026 CVE Vulnerabilities

60,149 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-54844HIGH7.5Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions.
CVE-2026-54843CRITICAL9.3Unauthenticated SQL Injection in MDTF <= 1.3.7 versions.
CVE-2026-54842HIGH8.1Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control S...
CVE-2026-54841HIGH7.5Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions.
CVE-2026-54838HIGH8.5Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions.
CVE-2026-54836CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows ...
CVE-2026-54830HIGH7.5Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions.
CVE-2026-54829HIGH7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt...
CVE-2026-54828HIGH7.5Unauthenticated Broken Access Control in Motors <= 1.4.109 versions.
CVE-2026-54823CRITICAL9.9Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.
CVE-2026-54822HIGH8.5Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.
CVE-2026-54821HIGH7.4Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.
CVE-2026-52690MEDIUM5.9Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of D...
CVE-2026-4526MEDIUM6.5In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logi...
CVE-2026-49506HIGH7.2Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted ...
CVE-2026-47154MEDIUM6.5In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating ...
CVE-2026-47153MEDIUM6.5In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-ze...
CVE-2026-47152MEDIUM6.5In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-ze...
CVE-2026-47151HIGH7.1In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock...
CVE-2026-47150HIGH7.1In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write a...
CVE-2026-47149MEDIUM6.5In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table re...
CVE-2026-47148MEDIUM6.5In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the me...
CVE-2026-47147HIGH7.1In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limi...
CVE-2026-47146MEDIUM6.5In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These ...
CVE-2026-47145MEDIUM6.5In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now