2026 CVE Vulnerabilities

67,186 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-86583HIGH8.8The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up ...
CVE-2026-81537HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to...
CVE-2026-81536HIGH7.7IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information ...
CVE-2026-81208HIGH7.7IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to imp...
CVE-2026-80423HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information ...
CVE-2026-75887HIGH7.5A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by man...
CVE-2026-57854——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-19125HIGH8.1The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includi...
CVE-2026-96556HIGH7.3A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerability is the function addcashier of the fi...
CVE-2026-82369HIGH8.6Insufficient input sanitization of shell metacharacters in the Brocade SANnav CLI scripting component permits authentica...
CVE-2026-80425HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du...
CVE-2026-80412HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to...
CVE-2026-80379HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du...
CVE-2026-75886HIGH7.2A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the Catalogd...
CVE-2026-6935HIGH7.8IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequatel...
CVE-2026-6928CRITICAL9.8IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can i...
CVE-2026-6925MEDIUM5.3IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to traverse directories on the system. An attacker could s...
CVE-2026-6794HIGH7.8IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management. A local ...
CVE-2026-6730HIGH7.8IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user cou...
CVE-2026-6721CRITICAL9.8IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is inc...
CVE-2026-6718MEDIUM6.2IBM Concert 1.0.0 through 3.0.0 is vulnerable to improper access control which allows unauthorized modification of appli...
CVE-2026-67405MEDIUM5.3RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, Neither the W...
CVE-2026-67404CRITICAL9.2RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, When no CA bu...
CVE-2026-67240LOW2.3RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, pattern_to_regex maps % -> .*? and _ ->...
CVE-2026-67235HIGH7.1RabbitMQ is a messaging and streaming broker. Prior to versions 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15, The content-h...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now