2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41932MEDIUM6.1Vvveb before 1.0.8.3 contains a stored cross-site scripting vulnerability in the customer signup flow where the Signup::...
CVE-2026-24712HIGH7.3Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection.
CVE-2026-24711MEDIUM5.3Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control.
CVE-2026-24710MEDIUM6.1Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS.
CVE-2026-21730MEDIUM6.1Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism. When an unaut...
CVE-2026-6638HIGH8.8SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table cre...
CVE-2026-6637HIGH8.8Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as th...
CVE-2026-6575MEDIUM4.3Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which cau...
CVE-2026-6479HIGH7.5Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX ...
CVE-2026-6478MEDIUM6.5Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover us...
CVE-2026-6477HIGH8.8Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lsee...
CVE-2026-6476HIGH7.2SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitra...
CVE-2026-6475HIGH8.8Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite loca...
CVE-2026-6474MEDIUM4.3Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server...
CVE-2026-6473HIGH8.8Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to un...
CVE-2026-6472MEDIUM5.4Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to...
CVE-2026-1630MEDIUM5.1WEBCON BPS is vulnerable to Reflected XSS via one of parameters used by "/openinmobileapp" endpoint. An attacker can sen...
CVE-2026-6008MEDIUM6.8Authorization bypass through User-Controlled key vulnerability in Im Park Information Technology, Electronics, Press, Pu...
CVE-2026-5798HIGH7.1Unsafe object reference (IDOR) in Stel Order v3.25.1 and earlier versions, specifically in the ‘/app/FrontController’ en...
CVE-2026-5790MEDIUM5.1Stored Cross-Site Scripting (XSS) in Stel Order v3.25.1 and earlier, located at the ‘/app/FrontController’ endpoint via ...
CVE-2026-4031HIGH7.5The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and ...
CVE-2026-4030HIGH8.1The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in...
CVE-2026-4029HIGH7.5The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up ...
CVE-2026-43644MEDIUM6.1podinfo through 6.11.2 contains a reflected cross-site scripting vulnerability in the /echo and /api/echo endpoints wher...
CVE-2026-45205MEDIUM5.3Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Config...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now