2026 CVE Vulnerabilities

64,751 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-83591HIGH7.2The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment ...
CVE-2026-62062HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This is...
CVE-2026-97818HIGH8.6phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.
CVE-2026-97737HIGH7.4In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leadin...
CVE-2026-97735HIGH8ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages ...
CVE-2026-97731HIGH7.1MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied...
CVE-2026-97730HIGH8.5In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dash...
CVE-2026-97646HIGH7.3A weakness has been identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. T...
CVE-2026-85082HIGH8.5Root Browser Classic 3.3.0 passes the path of a selected SQLite database to an operating-system shell without safely sep...
CVE-2026-87722HIGH8.7Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search query predicates (such as RegexProjectPredicate, ...
CVE-2026-87721HIGH8.7Uncontrolled Resource Consumption (CWE-400 / CWE-407) in the ANTLR 3 search query parser (QueryParser / Query.g) in Gerr...
CVE-2026-87720HIGH7.6Incorrect Authorization (CWE-863) in project name normalization (ProjectUtil.stripGitSuffix) and ProjectCache eviction l...
CVE-2026-85491HIGH8.8Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorizat...
CVE-2026-88388HIGH7.5Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace ...
CVE-2026-81630HIGH8.1The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update proce...
CVE-2026-14443HIGH8.4Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extensio...
CVE-2026-97326HIGH7.3A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this i...
CVE-2026-97324HIGH7.3A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoO...
CVE-2026-96883HIGH8.8pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 m...
CVE-2026-93354HIGH8.1Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers t...
CVE-2026-93289HIGH7.5The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute...
CVE-2026-85496HIGH8.8The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a ...
CVE-2026-84399HIGH8.8The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionalit...
CVE-2026-82566HIGH8.8The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can rem...
CVE-2026-82372HIGH8.5Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now