2026 CVE Vulnerabilities

61,679 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6239MEDIUM6.8A stack‑based buffer overflow vulnerability exists in Tapo C520WS v2 in the ONVIF CreateUsers service, where the device ...
CVE-2026-34123HIGH7On Tapo C520WS v2, restricted accounts (for example, hub users) are intended to execute only a limited set of low‑sensit...
CVE-2026-10038MEDIUM4.3The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vul...
CVE-2026-7654HIGH8.8The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in version...
CVE-2026-7523MEDIUM4.3The Alba Board plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. T...
CVE-2026-45409MEDIUM5.3Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in ...
CVE-2026-11431HIGH8.3A path traversal vulnerability exists in the Projects Service download endpoint shared by Altium Enterprise Server and A...
CVE-2026-11429CRITICAL10Two endpoints in the Vault Service ScriptsController, shared by Altium Enterprise Server and Altium 365, accept file upl...
CVE-2026-11424HIGH8.3A server-side request forgery (SSRF) vulnerability exists in a GraphQL service component shared by Altium Enterprise Ser...
CVE-2026-11416HIGH8.1MoviePilot contains a path traversal vulnerability in the AliPan, U115, and Rclone cloud storage download handlers where...
CVE-2026-36785HIGH7.5Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the page parameter...
CVE-2026-11423CRITICAL9.4A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of ...
CVE-2026-11422HIGH8.4Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom ren...
CVE-2026-46493HIGH7.5HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.1 use `uniqid` for generatin...
CVE-2026-46401MEDIUM5.3HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.0 suffer from an improper se...
CVE-2026-46400HIGH8.7HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 11.0.6 and prior to version 25....
CVE-2026-46398HIGH8.8HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 25.0.0 and prior to version 26....
CVE-2026-46397MEDIUM6.5HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an Authenticated Local Fil...
CVE-2026-46357MEDIUM6.5HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the HAX CMS NodeJS applica...
CVE-2026-45779CRITICAL9.8OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open X...
CVE-2026-45778MEDIUM5.4OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, an authenticated attac...
CVE-2026-45777CRITICAL9.8OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version ...
CVE-2026-45776MEDIUM4.3OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, a flaw in Open XDMoD's...
CVE-2026-45758CRITICAL9.6Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, ...
CVE-2026-45300HIGH7.4The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now