2026 CVE Vulnerabilities

64,473 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44321HIGH7.5free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management...
CVE-2026-44320HIGH7.3free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-callback ...
CVE-2026-44319HIGH7.5free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF terminates the entire pro...
CVE-2026-44318MEDIUM5.3free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's BSF PUT /nbsf-management/v1/s...
CVE-2026-44317MEDIUM6.5free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's PCF POST /npcf-policyauthoriz...
CVE-2026-44316HIGH7.5free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's PCF POST /npcf-smpolicycontro...
CVE-2026-44315CRITICAL9.4free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-pfd-manag...
CVE-2026-42790HIGH8.1Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS...
CVE-2026-42459HIGH7.5free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the free5GC UDM component fails to vali...
CVE-2026-42083HIGH8.2free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, PCF Npcf_SMPolicyControl missing authen...
CVE-2026-42082MEDIUM5.4free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not enforce the...
CVE-2026-42081HIGH7.1free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not verify the ...
CVE-2026-38945HIGH7.8Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary cod...
CVE-2026-38931MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp ...
CVE-2026-38930MEDIUM6.5OpenRapid RapidCMS v1.3.1 was discovered to contain an authentication bypass in the /template/default/menu.php component...
CVE-2026-9712LOW3.8When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, ra...
CVE-2026-9674MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows atta...
CVE-2026-6957MEDIUM4.9Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to constr...
CVE-2026-49103CRITICAL9.4Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. Thi...
CVE-2026-49102MEDIUM6.1Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes compo...
CVE-2026-49059MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing. ...
CVE-2026-49053MEDIUM5.3Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured ...
CVE-2026-49052MEDIUM4.3Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured ...
CVE-2026-49051MEDIUM4.3Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured...
CVE-2026-49047MEDIUM4.3Missing Authorization vulnerability in DearHive DearFlip allows Exploiting Incorrectly Configured Access Control Securit...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now