2026 CVE Vulnerabilities

61,772 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-39555HIGH8.1Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection. This issue affects Askk...
CVE-2026-39553HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-39552HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-35717MEDIUM6.3A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows auth...
CVE-2026-32685MEDIUM4.6Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write...
CVE-2026-32250MEDIUM4.3NamelessMC is website software for Minecraft servers. A Reflected Cross-Site Scripting (XSS) vulnerability was discovere...
CVE-2026-28116MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emilia Projects Pr...
CVE-2026-27351MEDIUM5.4Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploiting Incorrectly Configured Access Control ...
CVE-2026-10622HIGH8.2Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged fun...
CVE-2026-10621HIGH7.5Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archi...
CVE-2026-10611CRITICAL10An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In...
CVE-2026-8993MEDIUM6.5D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Applicatio...
CVE-2026-42685HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad WP Job Porta...
CVE-2026-42684CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Porta...
CVE-2026-42670HIGH7.5Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploitin...
CVE-2026-42669HIGH7.5Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly Configured Access Control Security Level...
CVE-2026-39551HIGH8.1Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbe...
CVE-2026-39550HIGH8.1Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects A...
CVE-2026-5422HIGH8.1A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check...
CVE-2026-5191MEDIUM5.4The Tiled Gallery Carousel Without JetPack plugin for WordPress is vulnerable to stored cross-site scripting via the 'da...
CVE-2026-46718MEDIUM6.5Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite. Thi...
CVE-2026-41115MEDIUM4.3An improper authorization vulnerability has been identified in Apache Kafka. The implementation of the CONSUMER_GROUP_D...
CVE-2026-34907MEDIUM5.1Wirtualna Uczelnia is vulnerable to Reflected Cross‑Site Scripting (XSS) due to insecure handling of the locale paramete...
CVE-2026-34906CRITICAL9.3Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to perform Remote Code Ex...
CVE-2026-10549MEDIUM5.3LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker with valid LDAP crede...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now