2026 CVE Vulnerabilities

45,094 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-35477CRITICAL9.9InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PA...
CVE-2026-2942CRITICAL9.8The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati...
CVE-2026-33466CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and po...
CVE-2026-31017CRITICAL9.1A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frapp...
CVE-2026-33229CRITICAL9.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8...
CVE-2026-31040CRITICAL9.8A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-fil...
CVE-2026-39394CRITICAL9.8CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-5300CRITICAL9.1Unauthenticated functionality in CoolerControl/coolercontrold <4.0.0 allows unauthenticated attackers to view and modif...
CVE-2026-39640CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This iss...
CVE-2026-39620CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell to ...
CVE-2026-39619CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Busiprof busiprof allows Upload a Web Shell to a Web ...
CVE-2026-39617CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forge...
CVE-2026-33088CRITICAL9.8Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute a...
CVE-2026-25776CRITICAL9.8Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute a...
CVE-2026-3535CRITICAL9.8The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type val...
CVE-2026-4003CRITICAL9.8The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in all ...
CVE-2026-3296CRITICAL9.8The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3...
CVE-2026-27143CRITICAL9.8Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the comp...
CVE-2026-39846CRITICAL9SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger re...
CVE-2026-34582CRITICAL9.1Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records...
CVE-2026-34078CRITICAL10Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths ...
CVE-2026-31789CRITICAL9.8Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflo...
CVE-2026-39397CRITICAL9.8@delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/...
CVE-2026-34045CRITICAL9.1Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP...
CVE-2026-33439CRITICAL9.8Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulner...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now