2026 CVE Vulnerabilities

45,004 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-57833HIGH8.6Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vu...
CVE-2026-57821HIGH8.1A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and ...
CVE-2026-56287HIGH8.1A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versi...
CVE-2026-35152HIGH8.8A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to a...
CVE-2026-57832HIGH8.7Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in EDocman < 3.9 - The Joomla extension EDocma...
CVE-2026-57831HIGH8.7Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla e...
CVE-2026-15804HIGH8.8The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can inject SQL commands ...
CVE-2026-15583HIGH8.6A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's enviro...
CVE-2026-14251HIGH7.7A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when ...
CVE-2026-42936HIGH8.4The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory wh...
CVE-2026-12512HIGH8.6The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before us...
CVE-2026-12281HIGH8.1The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without ...
CVE-2026-8920HIGH8.5Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wa...
CVE-2026-8919HIGH7.2Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local us...
CVE-2026-15029HIGH8.4Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Mana...
CVE-2026-13585HIGH8.2Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in ...
CVE-2026-15752HIGH7.3A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is a...
CVE-2026-59733HIGH8.8Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1...
CVE-2026-54684HIGH7jadx is a Dex to Java decompiler. From 1.5.2 to 1.5.5, a malicious .xapk file can cause jadx to write attacker-controlle...
CVE-2026-54572HIGH8.8Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1...
CVE-2026-50130HIGH8.8Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From ...
CVE-2026-49981HIGH8.2Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is c...
CVE-2026-48808HIGH7.5Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but...
CVE-2026-48352HIGH7.5CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application de...
CVE-2026-48351HIGH7.5CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application de...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now