2026 CVE Vulnerabilities

61,122 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-35162MEDIUM6.5Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileg...
CVE-2026-35067HIGH8Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileg...
CVE-2026-35066HIGH7.1Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileg...
CVE-2026-35065HIGH8.8Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Missing Authentication for Critical Function vulnerabi...
CVE-2026-32804HIGH8.1Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthentic...
CVE-2026-22283HIGH7.5Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Inclusion of Functionality from Untrusted Control Sph...
CVE-2026-12528MEDIUM5.4A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Acce...
CVE-2026-11311MEDIUM6.5When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX...
CVE-2026-10850MEDIUM5.4Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when cre...
CVE-2026-9591MEDIUM6.9Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthent...
CVE-2026-55738HIGH8.8A stack-based buffer overflow exists in the raw_to_header function in src/microtar.c in rxi microtar 0.1.0. The function...
CVE-2026-54819CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listd...
CVE-2026-54818HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimsta...
CVE-2026-54817MEDIUM6.5Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recover...
CVE-2026-54816HIGH7.5Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remote Code ...
CVE-2026-54815CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shi...
CVE-2026-54814HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-54813HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force S...
CVE-2026-54809CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme GIFT4U ...
CVE-2026-54808CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Trave...
CVE-2026-54417HIGH8.7An integer overflow in the mtar_next function in src/microtar.c in rxi microtar 0.1.0 allows a remote attacker to cause ...
CVE-2026-54193HIGH7.7Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.
CVE-2026-52716MEDIUM6.5Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.
CVE-2026-52707HIGH8.1Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.
CVE-2026-49268CRITICAL9.1A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm c...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now