2026 CVE Vulnerabilities

61,683 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-46390MEDIUM6.9HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 2.0.0 and prior to version 26.0...
CVE-2026-46389CRITICAL9.8UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Co...
CVE-2026-10580CRITICAL9.8The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrat...
CVE-2026-50733HIGH8.8Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown content with eval(), a...
CVE-2026-49493HIGH8.8Markdown Preview Enhanced before 0.8.28 parses Bitfield fenced code blocks with interpretJS(), which evaluates the block...
CVE-2026-49492HIGH8.8Markdown Preview Enhanced before 0.8.28 opens external files and links from the preview through a shell and does not val...
CVE-2026-45750CRITICAL9Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v...
CVE-2026-45749HIGH8.1Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST ...
CVE-2026-45748CRITICAL9.8Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST ...
CVE-2026-45746CRITICAL9Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v...
CVE-2026-45745HIGH8Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Starting i...
CVE-2026-45744CRITICAL9.9Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v...
CVE-2026-45743HIGH8.1Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. 16 file-ma...
CVE-2026-45327HIGH8.2TinyIce is a streaming server for audio and video. In versions 0.8.95 through 2.4.1, missing authentication on WebRTC in...
CVE-2026-45291HIGH7.5Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1....
CVE-2026-45290HIGH7.5Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1....
CVE-2026-36501HIGH7.5An issue in the Externalizable.readExternal() component of Controller v12.0.5 allows attackers to cause a Denial of Serv...
CVE-2026-36500CRITICAL9.1An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory t...
CVE-2026-2379HIGH8.2On affected platforms with hardware IPSec support running Arista EOS with certain IPsec features enabled, EOS may exhibi...
CVE-2026-11344HIGH7.3A vulnerability was found in code-projects Vehicle Management System 1.0. This impacts an unknown function of the file n...
CVE-2026-11342HIGH7.3A vulnerability has been found in code-projects Hotel and Tourism Reservation System 1.0. This affects an unknown functi...
CVE-2026-11341MEDIUM6.3A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boaf...
CVE-2026-8714MEDIUM6.5A denial-of-service vulnerability exists in the RTSP server component of TP-Link Tapo C520WS v2 due to improper handling...
CVE-2026-7473MEDIUM6.9On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LA...
CVE-2026-48112MEDIUM6.57-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain a heap out-of-bounds read in...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now