2026 CVE Vulnerabilities

61,771 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41860HIGH8.8CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpReq...
CVE-2026-41859HIGH7.8A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth heade...
CVE-2026-41858HIGH7.5Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities...
CVE-2026-41011HIGH8.7PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz")...
CVE-2026-10597MEDIUM6.9OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote a...
CVE-2026-8653MEDIUM6.5The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in ...
CVE-2026-7764MEDIUM6.8An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versio...
CVE-2026-10737HIGH7.5The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability ...
CVE-2026-8722MEDIUM6.5Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked fo...
CVE-2026-10783LOW2.5A security flaw has been discovered in gradio-app gradio 6.14.0. This affects the function save_audio_to_cache of the co...
CVE-2026-2596Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-10777HIGH7.3A vulnerability was identified in ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08. Af...
CVE-2026-10775MEDIUM5.3A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_h...
CVE-2026-46447HIGH7.7OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info o...
CVE-2026-22055HIGH8.8Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low p...
CVE-2026-22054HIGH8.8Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with l...
CVE-2026-10771HIGH7.3A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-...
CVE-2026-50033HIGH7.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock D...
CVE-2026-44682HIGH7.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock D...
CVE-2026-44609HIGH7.3Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock D...
CVE-2026-43924MEDIUM4.8FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Redirect module doe...
CVE-2026-42061HIGH7.3Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected...
CVE-2026-40495MEDIUM6.9FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 leak the exact system v...
CVE-2026-37700MEDIUM4.1Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via t...
CVE-2026-26825MEDIUM5.3A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reacha...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now