2026 CVE Vulnerabilities

60,206 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-10711HIGH8.8Missing authentication for critical function vulnerability in AKIN Software Computer Import Export Industry and Trade Lt...
CVE-2026-4983MEDIUM5.4Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content...
CVE-2026-11374CRITICAL9In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated...
CVE-2026-9733CRITICAL9.1Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no...
CVE-2026-10521HIGH8.6An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user, ...
CVE-2026-8379HIGH7.5The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file dow...
CVE-2026-8378MEDIUM5.4The Frontend File Manager Plugin WordPress plugin through 23.6 does not sanitise nor escape a filename submitted to the ...
CVE-2026-8172HIGH7.1The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecting it...
CVE-2026-8163HIGH8.8The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using t...
CVE-2026-7842MEDIUM6.8The Infility Global Infility Global WordPress plugin before 2.15.20 for WordPress does not sanitize or validate the orde...
CVE-2026-12866CRITICAL9.8All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execu...
CVE-2026-55655MEDIUM6.1A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding ...
CVE-2026-55654LOW3.7A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic...
CVE-2026-55653MEDIUM6.5A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group ...
CVE-2026-11833HIGH8.2Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing t...
CVE-2026-10658HIGH7.1bt_iso_recv() in subsys/bluetooth/host/iso.c pulled the ISO SDU header (4 bytes) or, when the timestamp flag is set, the...
CVE-2026-10651MEDIUM6.5bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the type-...
CVE-2026-10645MEDIUM5.5The Zephyr ext2 filesystem driver (subsys/fs/ext2) trusted the on-disk directory entry fields de_rec_len and de_name_len...
CVE-2026-54236MEDIUM5.3vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, the fix for CVE-2026-22778...
CVE-2026-54235MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, ll temperature validation ...
CVE-2026-54233MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, vLLM's /v1/audio/transcrip...
CVE-2026-54232HIGH8.8vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulner...
CVE-2026-53923HIGH7.5vLLM is an inference and serving engine for large language models (LLMs). From 0.5.5 until 0.23.1rc0, integer truncation...
CVE-2026-48746CRITICAL9.1vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in AS...
CVE-2026-47155MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, vLLM's revision pinning contr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now