2026 CVE Vulnerabilities

64,705 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-22315——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-22314HIGH7.9Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesa...
CVE-2026-0857MEDIUM4.4Use of a Password Hash With Insufficient Computational Effort in Mesalvo MEONA (MEONA Server and MEONA Client) for user ...
CVE-2026-0856HIGH7.8Improper Access Control vulnerability in Mesalvo MEONA (MEONA Client and MEONA Server) allows an authenticated MEONA use...
CVE-2026-9064HIGH7.5A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an uppe...
CVE-2026-6728MEDIUM5.3The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includ...
CVE-2026-44933HIGH8.5`PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/` (the system root) i...
CVE-2026-44608MEDIUM5.9NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain...
CVE-2026-44390MEDIUM5.3NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets t...
CVE-2026-42960CRITICAL10NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authori...
CVE-2026-42959HIGH7.5NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that...
CVE-2026-42944HIGH7.5NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when enco...
CVE-2026-42923MEDIUM5.3NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator where the code path to...
CVE-2026-42534MEDIUM5.3NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purp...
CVE-2026-41292HIGH7.5NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsin...
CVE-2026-41054HIGH7.8In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\0/sys/ent...
CVE-2026-40622HIGH7.5NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of a...
CVE-2026-35070MEDIUM6.7Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization of Special Elements used...
CVE-2026-33278CRITICAL9.8NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables de...
CVE-2026-32792MEDIUM5.3NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNS...
CVE-2026-9065CRITICAL9.3SureCart version prior to 4.2.1 are vulnerable to authenticated SQL injection via multiple parameters ('model_name', 'mo...
CVE-2026-9059CRITICAL9.3NextGEN Gallery version prior to 4.2.1 are vulnerable to authenticated SQL injection via the 'orderby' parameter on the ...
CVE-2026-6405MEDIUM4.3The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) ...
CVE-2026-5200HIGH8.8The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v...
CVE-2026-7385MEDIUM5.8The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email addresses and post au...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now