2026 CVE Vulnerabilities

64,734 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-46724MEDIUM5.9The file indexer does not normalize the configured directory path. A backend user with permission to edit indexer config...
CVE-2026-46723MEDIUM5.9The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backe...
CVE-2026-46722MEDIUM5.9The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document place...
CVE-2026-46721MEDIUM6.9The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on th...
CVE-2026-46586HIGH8.8Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluate...
CVE-2026-45434CRITICAL9.8Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution T...
CVE-2026-45187MEDIUM6.5Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users...
CVE-2026-41919CRITICAL9.1Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. Thi...
CVE-2026-35086MEDIUM6.5Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue a...
CVE-2026-31986CRITICAL9.1Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. U...
CVE-2026-31910HIGH7.5Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Us...
CVE-2026-31909HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issue affects Apache OFB...
CVE-2026-31906MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz. Thi...
CVE-2026-31388MEDIUM5.3Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affects Apache OFBiz: bef...
CVE-2026-31387MEDIUM5.3Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are rec...
CVE-2026-31380MEDIUM6.5Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') v...
CVE-2026-31379MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname ...
CVE-2026-31378MEDIUM6.5Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are r...
CVE-2026-2611CRITICAL9.6In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. ...
CVE-2026-29226HIGH7.3Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations. This issue affects A...
CVE-2026-29220MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issu...
CVE-2026-29207MEDIUM6.5Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects...
CVE-2026-44408MEDIUM6.3There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an...
CVE-2026-8922MEDIUM5.4A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies are configured, Key...
CVE-2026-4885CRITICAL9.8The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file typ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now