2026 CVE Vulnerabilities

61,791 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-10274MEDIUM6.3A vulnerability was determined in indrasishbanerjee aem-mcp-server up to b5f833aef9b5dfd17a5991b3b18a8a11edbdc583. This ...
CVE-2026-10273HIGH7.3A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBui...
CVE-2026-10272MEDIUM6.5A vulnerability has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The imp...
CVE-2026-10271MEDIUM6.3A flaw has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The affected ele...
CVE-2026-10270HIGH7.5A vulnerability was detected in D-Link DI-7001 MINI up to 19.09.19A1. Impacted is the function sprintf of the file /http...
CVE-2026-10269MEDIUM6.3A security vulnerability has been detected in decolua 9router up to 0.4.0. This issue affects the function isAuthenticat...
CVE-2026-10268LOW3.3A weakness has been identified in janet-lang janet up to 1.41.0. This vulnerability affects the function unmarshal_one_f...
CVE-2026-10118HIGH7.8A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious...
CVE-2026-8931CRITICAL9.4A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3.
CVE-2026-48879CRITICAL9.8Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from ...
CVE-2026-48866CRITICAL9.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravit...
CVE-2026-48865HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPre...
CVE-2026-48839HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Stat...
CVE-2026-48559MEDIUM5.4Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability that allows attackers ...
CVE-2026-42683HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBookin...
CVE-2026-42682CRITICAL9.1Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Sec...
CVE-2026-42681HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf.Com e2pdf al...
CVE-2026-42680CRITICAL9.8Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows P...
CVE-2026-42251HIGH8.7Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker access to FTP server that hosted the applicat...
CVE-2026-37221HIGH7.5FlexRIC v2.0.0 crashes when receiving a RIC_SUBSCRIPTION_RESPONSE with an unknown ric_id that has no corresponding pendi...
CVE-2026-37220HIGH7.5FlexRIC v2.0.0 crashes when an SCTP association is closed before an E2_SETUP_REQUEST is sent. The near-RT RIC assumes a ...
CVE-2026-10533MEDIUM5A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQ...
CVE-2026-10267LOW3.3A security flaw has been discovered in janet-lang janet up to 1.41.0. This affects the function doframe of the file src/...
CVE-2026-10265MEDIUM6.3A vulnerability was identified in itsourcecode Content Management System 1.0. Affected by this issue is some unknown fun...
CVE-2026-10264LOW3.5A vulnerability was determined in lharries whatsapp-mcp 0.0.1. Affected by this vulnerability is the function SendMessag...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now