2026 CVE Vulnerabilities

61,264 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5242HIGH8.8Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy Library allows Code...
CVE-2026-5233HIGH7.1Improper Control of Interaction Frequency vulnerability in MIA Technology Inc. Pizzy Library allows Flooding. This issu...
CVE-2026-5230HIGH7.1Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library allows Exploiting Inco...
CVE-2026-5079HIGH7.5Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested fi...
CVE-2026-52704CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder a...
CVE-2026-49111HIGH8.8Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. This issue affe...
CVE-2026-49064HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Da...
CVE-2026-49062HIGH8.8Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Ex...
CVE-2026-48969MEDIUM6.5Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions.
CVE-2026-5482CRITICAL9.3Responsive FileManager's allows an unauthenticated attacker to upload files of any type and extension without restrictio...
CVE-2026-49757CRITICAL9.2Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users...
CVE-2026-34030MEDIUM6.9The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, does not sufficiently validate the branch code wh...
CVE-2026-34029MEDIUM6.8The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a hard-coded cryptographic key in the Sa...
CVE-2026-34028MEDIUM6.9The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, exposes web-accessible file paths that are not pr...
CVE-2026-34027MEDIUM5.3The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains insufficient server-side file type valid...
CVE-2026-34026HIGH7.1Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a path traversal vulnerability in the docume...
CVE-2026-34025MEDIUM5.3The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an IP restriction bypass vulnerability i...
CVE-2026-34024HIGH8.6The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains missing authorization checks on multiple...
CVE-2026-34023HIGH7.1The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an incorrect authorization vulnerability...
CVE-2026-34022HIGH7.1The Wertheim SafeController Family 65000, Controller 65000 - AssemblyVersion 6.11.8130.22319, uses weak custom cryptogra...
CVE-2026-34021HIGH8.6The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485 communication between t...
CVE-2026-12057HIGH7.8When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some d...
CVE-2026-50100HIGH8.5Multiple printer drivers provided by Ricoh Company, Ltd. and KONICA MINOLTA JAPAN, INC. contain a privilege escalation v...
CVE-2026-44188MEDIUM5.3A flaw was found in Ansible Lightspeed. This vulnerability, related to insufficient session expiration, allows a remote ...
CVE-2026-11860HIGH7.5Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. Thi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now