2026 CVE Vulnerabilities

64,616 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40840HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the VerifyCreateLicences...
CVE-2026-40839HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getComponentScalings...
CVE-2026-40838HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getDeviceScalings fu...
CVE-2026-40837HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectScalings f...
CVE-2026-40836HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the inmessage model due ...
CVE-2026-40835HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the saveObjectFromData f...
CVE-2026-40834HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dash_layout.php file...
CVE-2026-40833HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dash.php files saveD...
CVE-2026-40832HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getDevicegroups func...
CVE-2026-40831HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the Easy View due to imp...
CVE-2026-40830HIGH7A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the admin.mbnetj.php fil...
CVE-2026-40829HIGH7A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the view.html.php files ...
CVE-2026-40828HIGH7A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DeleteSysLogEntry fu...
CVE-2026-40827HIGH7A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _RemoveRequest funct...
CVE-2026-2237MEDIUM5.5A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager ...
CVE-2026-8942MEDIUM4.3The MetaMagic SEO Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2026-8906MEDIUM6.1The WP Promoter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2026-8832HIGH8.8The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for WordPress is vulnerab...
CVE-2026-8143HIGH7.2The HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hb_country_iso', 'hb_usa_state_iso'...
CVE-2026-8042MEDIUM6.4The Github Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'repo' shortcode attribut...
CVE-2026-7618MEDIUM4.9The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to time-based blind SQL Injection vi...
CVE-2026-6169HIGH7.2The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, ...
CVE-2026-49001MEDIUM5.3Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cro...
CVE-2026-41704MEDIUM6.8AgentClient#handle_method (lines 264-303) processes every NATS reply. It calls inject_compile_log (line 273) on every re...
CVE-2026-41009MEDIUM5.8When the director sends a long-running request (e.g. compile_package), the agent's reply JSON is consumed by AgentClient...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now