2026 CVE Vulnerabilities

44,976 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-14741HIGH7.5HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date. parse_da...
CVE-2026-12715HIGH8.5Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an at...
CVE-2026-63094HIGH8.1SigNoz before 0.134.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated...
CVE-2026-63093HIGH8.8Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbit...
CVE-2026-51082HIGH7.2A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager be...
CVE-2026-9592HIGH7.5SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user sess...
CVE-2026-7488HIGH7.5Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embed...
CVE-2026-16016HIGH7.3A vulnerability was identified in poco-ai poco-claw up to 0.5.4. This issue affects the function run_task of the file ex...
CVE-2026-8396HIGH7.5Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NetGIS allows Serialized Dat...
CVE-2026-7189HIGH7.5Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessin...
CVE-2026-16014HIGH7.3A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the compo...
CVE-2026-13410HIGH8.2Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled. The default user agent is in...
CVE-2026-59695HIGH8.3Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the f...
CVE-2026-59694HIGH8.3Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the...
CVE-2026-59252HIGH8.2Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the f...
CVE-2026-22104HIGH7.1Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows...
CVE-2026-11961HIGH8.1The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted d...
CVE-2026-11575HIGH7.5The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming paymen...
CVE-2026-13765HIGH7.5The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive...
CVE-2026-13352HIGH8.8The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres...
CVE-2026-15395HIGH7.2The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2026-62387HIGH7.1The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its default C...
CVE-2026-62386HIGH8.2The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query...
CVE-2026-62238HIGH8.8OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export endpoint ...
CVE-2026-62234HIGH8.4Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.w...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now