2026 CVE Vulnerabilities

61,327 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-11846HIGH8.1The  iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerabilit...
CVE-2026-11845HIGH8.6The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injection vulnerability, al...
CVE-2026-11844MEDIUM6.9The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Arbitrary File Read vulnerability, all...
CVE-2026-12058MEDIUM5.3The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed.
CVE-2026-11535CRITICAL9.4An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unaut...
CVE-2026-9271MEDIUM5.9Vulnerability Title
CVE-2026-9269LOW3.5The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some o...
CVE-2026-12060MEDIUM6.9Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticate...
CVE-2026-12059HIGH8.8The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenticated ...
CVE-2026-45169HIGH8.6Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a v...
CVE-2026-44892HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final,...
CVE-2026-48613MEDIUM5.9SQL injection vulnerability in phpBB profile field migration due to improper handling of user-supplied profile field dat...
CVE-2026-48612HIGH8Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow an...
CVE-2026-48611CRITICAL9.8Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or ...
CVE-2026-48610HIGH8.1Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control ...
CVE-2026-47370CRITICAL9.9A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability...
CVE-2026-47369CRITICAL9.9A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability...
CVE-2026-47368HIGH8.6A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices runni...
CVE-2026-47367CRITICAL9.9A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability...
CVE-2026-47366HIGH7.2Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) al...
CVE-2026-47365CRITICAL9.9Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated...
CVE-2026-20746MEDIUM6.3Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust j...
CVE-2026-9125MEDIUM6.4The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the ...
CVE-2026-45170HIGH8.8Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios...
CVE-2026-11933HIGH8.8A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now