2026 CVE Vulnerabilities

62,782 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-42679MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classifie...
CVE-2026-42678HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / Stell...
CVE-2026-42677HIGH7.5Missing Authorization vulnerability in Ben Balter WP Document Revisions allows Exploiting Incorrectly Configured Access ...
CVE-2026-42676MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred allows Stor...
CVE-2026-42675HIGH7.3Missing Authorization vulnerability in Themefic Hydra Booking allows Exploiting Incorrectly Configured Access Control Se...
CVE-2026-42674HIGH7.5Authentication Bypass by Spoofing vulnerability in AAM Plugin Advanced Access Manager allows URL Encoding. This issue a...
CVE-2026-42673HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity ...
CVE-2026-42672CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit W...
CVE-2026-42671MEDIUM6.5Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Securi...
CVE-2026-38950HIGH7.8An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrary code via crafted model checkpoint files. ...
CVE-2026-37227HIGH7.5FlexRIC v2.0.0 contains reachable assert(0) calls in stub message handlers for whitelisted but unimplemented E2AP messag...
CVE-2026-37225HIGH7.5FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST with an empty ricEventTriggerDefinition fi...
CVE-2026-37224HIGH7.5FlexRIC v2.0.0 crashes when receiving a duplicate E2_SETUP_REQUEST from the same or spoofed E2 Node. The iApp registry e...
CVE-2026-37223HIGH7.5FlexRIC v2.0.0 contains a reachable assertion in the iApp message dispatcher. The dispatcher validates incoming E2AP mes...
CVE-2026-37222HIGH7.5FlexRIC v2.0.0 uses hardcoded assertions to validate Information Element (IE) counts in decoded E2AP messages. A remote ...
CVE-2026-10275MEDIUM5A flaw has been found in OpenSC up to 0.26.1. This affects the function test_kpgen_certwrite of the file src/tools/pkcs1...
CVE-2026-10274MEDIUM6.3A vulnerability was determined in indrasishbanerjee aem-mcp-server up to b5f833aef9b5dfd17a5991b3b18a8a11edbdc583. This ...
CVE-2026-10273HIGH7.3A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBui...
CVE-2026-10272MEDIUM6.5A vulnerability has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The imp...
CVE-2026-10271MEDIUM6.3A flaw has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The affected ele...
CVE-2026-10270HIGH7.5A vulnerability was detected in D-Link DI-7001 MINI up to 19.09.19A1. Impacted is the function sprintf of the file /http...
CVE-2026-10269MEDIUM6.3A security vulnerability has been detected in decolua 9router up to 0.4.0. This issue affects the function isAuthenticat...
CVE-2026-10268LOW3.3A weakness has been identified in janet-lang janet up to 1.41.0. This vulnerability affects the function unmarshal_one_f...
CVE-2026-10118HIGH7.8A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious...
CVE-2026-8931CRITICAL9.4A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now