2026 CVE Vulnerabilities

64,705 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6566MEDIUM4.3The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Insecure Direct ...
CVE-2026-5776MEDIUM6.1The Email Encoder WordPress plugin before 2.4.7 does not escape email addresses retrieved via user input, allowing unau...
CVE-2026-47784HIGH8.1In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because me...
CVE-2026-47783HIGH8.1In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a ...
CVE-2026-44392MEDIUM5.3Missing authorization vulnerability exists in Movable Type. Under certain conditions, when a user without administrator ...
CVE-2026-2955MEDIUM6.4The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '...
CVE-2026-9057HIGH8.2A broken access control issue has been identified in the Talend Administration Center, that allows a user with “View” pe...
CVE-2026-9056MEDIUM5.4A stored cross-site scripting vulnerability has been found in the Talend Administration Center. An attacker with permiss...
CVE-2026-7522HIGH8.8The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion in versions up to, an...
CVE-2026-5075MEDIUM4.3The All in One SEO plugin for WordPress is vulnerable to Sensitive Information Exposure via 'internalOptions' localized ...
CVE-2026-9010HIGH7.5The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameter...
CVE-2026-9003HIGH8.7E-LAN Hybrid Recording System developed by TONNET has a SQL Injection vulnerability, allowing unauthenticated remote att...
CVE-2026-7637CRITICAL9.8The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deseria...
CVE-2026-7460HIGH7.4mailcow-dockerized contains a stored cross-site scripting vulnerability in the administrator Queue Manager. The Queue Ma...
CVE-2026-24215HIGH7.5NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, where an attacker could cause uncontrolled ...
CVE-2026-24214CRITICAL9.8NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer ove...
CVE-2026-24213CRITICAL9.8NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-boun...
CVE-2026-24210HIGH7.5NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an integer overflow. A successful ...
CVE-2026-24209HIGH7.5NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successf...
CVE-2026-24208HIGH7.5NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successf...
CVE-2026-24207CRITICAL9.8NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A succes...
CVE-2026-24206CRITICAL9.8NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A succes...
CVE-2026-24163CRITICAL9.8NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deseri...
CVE-2026-24160HIGH7.5NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked return value to a n...
CVE-2026-24142CRITICAL9.8NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful ex...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now