2026 CVE Vulnerabilities

61,215 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-9261CRITICAL9.8Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier
CVE-2026-9260CRITICAL9.8Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
CVE-2026-9259CRITICAL9.8Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier
CVE-2026-9258CRITICAL9.8Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
CVE-2026-53430HIGH8.7Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-grpc grpc (GRPC.Compressor.Gzip...
CVE-2026-48854HIGH8.7Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers ...
CVE-2026-48853CRITICAL9.2Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grp...
CVE-2026-48723HIGH7.8The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on BrowserStack. Versions pri...
CVE-2026-48599HIGH7.6Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to acc...
CVE-2026-12205CRITICAL9.1Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DS...
CVE-2026-5064HIGH8.5Potential security vulnerabilities have been identified in the HP One Agent for certain HP PC products, which might all...
CVE-2026-48714CRITICAL9.1i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno...
CVE-2026-48713CRITICAL9.1Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missi...
CVE-2026-48157MEDIUM6.1Slim is a PHP micro framework that enables users to write simple web applications and APIs. In versions 4.4.0 through 4....
CVE-2026-48017HIGH8.8DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate...
CVE-2026-12087CRITICAL9.1Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the l...
CVE-2026-11832CRITICAL9.1Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was genera...
CVE-2026-9691CRITICAL9.8Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja For...
CVE-2026-52703CRITICAL9.6Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.
CVE-2026-52702HIGH7.1Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions.
CVE-2026-52700HIGH8.5Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.
CVE-2026-52699HIGH7.5Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions.
CVE-2026-52697HIGH8.5Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.
CVE-2026-52695HIGH7.5Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.
CVE-2026-52694HIGH7.5Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now