2026 CVE Vulnerabilities

64,659 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-9342MEDIUM6.3A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. Impacted is an un...
CVE-2026-9306LOW3.7A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourne...
CVE-2026-9305MEDIUM6.3A weakness has been identified in QuantumNous new-api up to 0.12.1. The impacted element is the function SearchUserTopUp...
CVE-2026-9304MEDIUM5A security flaw has been discovered in calcom cal.diy up to 4.9.4. The affected element is the function validateUrlForSS...
CVE-2026-9303MEDIUM4.3A vulnerability was identified in calcom cal.diy up to 4.9.4. Impacted is an unknown function. The manipulation leads to...
CVE-2026-9302MEDIUM6.3A vulnerability was determined in 546669204 vps-inventory-monitoring up to 98c00b370668c96ae75e91c15548d9ea113652d9. Thi...
CVE-2026-9301MEDIUM6.3A vulnerability was found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGRe...
CVE-2026-9300MEDIUM6.3A vulnerability has been found in omec-project amf up to 2.1.1. This affects an unknown part of the component NGSetupReq...
CVE-2026-46300HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coa...
CVE-2026-43503HIGH8.8In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through f...
CVE-2026-9299MEDIUM6.3A flaw has been found in omec-project amf up to 2.1.1. Affected by this issue is the function PDUSessionResourceModifyIn...
CVE-2026-9298MEDIUM6.3A vulnerability was detected in omec-project amf up to 2.1.1. Affected by this vulnerability is an unknown functionality...
CVE-2026-9297MEDIUM6.3A security vulnerability has been detected in Edimax BR-6428NS 1.10. Affected is the function formWlbasic of the file /g...
CVE-2026-9296MEDIUM6.3A weakness has been identified in Edimax BR-6428NS 1.10. This impacts the function system of the file /goform/formWlanM ...
CVE-2026-9295HIGH8.8A security flaw has been discovered in Edimax BR-6428NS 1.10. This affects the function formWirelessTbl of the file /gof...
CVE-2026-9294HIGH8.8A vulnerability was identified in Edimax BR-6428NS 1.10. The impacted element is the function formWanTcpipSetup of the f...
CVE-2026-9284HIGH8.2The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information di...
CVE-2026-6898HIGH8.8The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2026-6897HIGH8.8The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2026-6895HIGH8.8The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclos...
CVE-2026-6419HIGH8.8The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up ...
CVE-2026-47280CRITICAL9.8Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a net...
CVE-2026-45659HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-42901CRITICAL10Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-42827HIGH7.5Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now