2026 CVE Vulnerabilities

64,732 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-42096HIGH8.8Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to lack of per...
CVE-2026-23558HIGH7.8The adjustments made for XSA-379 as well as those subsequently becoming XSA-387 still left a race window, when a HVM or ...
CVE-2026-23557MEDIUM6.5Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() tri...
CVE-2026-8912HIGH7.5The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to...
CVE-2026-4883CRITICAL9.8The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the...
CVE-2026-7860LOW1.6A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes ...
CVE-2026-7571HIGH7.1A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a secur...
CVE-2026-7507HIGH7.5A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could expl...
CVE-2026-7504HIGH8.1A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an atta...
CVE-2026-7307HIGH7.5A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security ...
CVE-2026-4630MEDIUM6.8A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerabi...
CVE-2026-45442MEDIUM4.3Missing Authorization vulnerability in Brainstorm Force Presto Player allows Exploiting Incorrectly Configured Access Co...
CVE-2026-43493CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG reques...
CVE-2026-43492MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: lib/crypto: mpi: Fix integer underflow in mpi_read_...
CVE-2026-43491MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: qrtr: ns: Limit the maximum server registratio...
CVE-2026-37982MEDIUM6.8A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsAction...
CVE-2026-37981MEDIUM4.3A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows...
CVE-2026-37979MEDIUM6.5A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection ...
CVE-2026-37978MEDIUM4.9A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking th...
CVE-2026-8827HIGH8.2The AddressRepository::getSqlQuery() method constructs a database query without properly sanitizing user input, leading ...
CVE-2026-8727HIGH7.1The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An ...
CVE-2026-8726HIGH8.2The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated...
CVE-2026-46725CRITICAL9.2The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. ...
CVE-2026-46724MEDIUM5.9The file indexer does not normalize the configured directory path. A backend user with permission to edit indexer config...
CVE-2026-46723MEDIUM5.9The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backe...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now