2026 CVE Vulnerabilities

64,702 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44048HIGH8.8A stack-based buffer overflow via UCS-2 type confusion in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a rem...
CVE-2026-44047HIGH8.8An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a remote authenticated a...
CVE-2026-6279CRITICAL9.8The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP F...
CVE-2026-2734MEDIUM6.5In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions` G...
CVE-2026-1543MEDIUM6.4The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in ...
CVE-2026-4811MEDIUM4.9The WPB Floating Menu & Categories for WordPress – Sticky Side Menu with Icons plugin for WordPress is vulnerable to Sto...
CVE-2026-9152CRITICAL10A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search ind...
CVE-2026-48172CRITICAL9.8LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild i...
CVE-2026-1881MEDIUM4.3The Broadstreet plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includ...
CVE-2026-9149MEDIUM6.5A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted ...
CVE-2026-40165HIGH8.7authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 ...
CVE-2026-9150MEDIUM6.5A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser w...
CVE-2026-8399——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-47782MEDIUM4.6Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL v...
CVE-2026-47372CRITICAL9.1Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. These versions use the buil...
CVE-2026-40102MEDIUM6.5Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-cont...
CVE-2026-40094MEDIUM4.3nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and prior, network...
CVE-2026-40092HIGH7.5nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and below, a malic...
CVE-2026-39960MEDIUM5.4Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and below contain flawed logic that cause...
CVE-2026-8632HIGH7.8A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vul...
CVE-2026-8631CRITICAL9.8A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vul...
CVE-2026-47373HIGH7.5Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks. These versions use Perl's built-in e...
CVE-2026-9144HIGH8.4Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a stored cross-site scripting vulnerability in the embedde...
CVE-2026-9141CRITICAL9.8Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedded web...
CVE-2026-9139CRITICAL9.8Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability in the embedded web ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now