2026 CVE Vulnerabilities

61,333 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40987HIGH7.1A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the ...
CVE-2026-40986MEDIUM4.8Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not...
CVE-2026-10795HIGH8.1The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all version...
CVE-2026-40985MEDIUM6.4Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions....
CVE-2026-35273CRITICAL9.8Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mana...
CVE-2026-2827MEDIUM4.7The Open User Map PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'oum_location_notificati...
CVE-2026-53465MEDIUM6.2ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25...
CVE-2026-53464MEDIUM4ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25...
CVE-2026-53463MEDIUM4.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-53462MEDIUM5.9ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-53461HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-53460HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-52726HIGH7.5Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.23.2 and prior to v...
CVE-2026-50223HIGH8.8Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenti...
CVE-2026-49219MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-49218HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-48994MEDIUM5.9ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-48734MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-48733MEDIUM4.7ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-48724MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-24...
CVE-2026-47734MEDIUM5.7Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.1.0 and prior to ve...
CVE-2026-47712LOW3.3Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to v...
CVE-2026-47342HIGH8.8A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privile...
CVE-2026-47213MEDIUM6.5Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers ...
CVE-2026-47166MEDIUM5.7ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now