2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44195MEDIUM6.5OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler...
CVE-2026-44194CRITICAL9.1OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE)...
CVE-2026-44193CRITICAL9.1OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_se...
CVE-2026-42463HIGH8.1SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cr...
CVE-2026-40328——Rejected reason: This CVE is a duplicate of another CVE.
CVE-2026-40327——Rejected reason: This CVE is a duplicate of another CVE.
CVE-2026-32993HIGH8.3Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated a...
CVE-2026-32992HIGH8.2SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the...
CVE-2026-29205HIGH8.6Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdav...
CVE-2026-8328MEDIUM5.9The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to rep...
CVE-2026-45714CRITICAL9.1CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulne...
CVE-2026-45708HIGH7.2CubeCart is an ecommerce software solution. Prior to 6.7.3, an admin with documents edit permission can save raw <?php …...
CVE-2026-45229HIGH8.8Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authenticated...
CVE-2026-45228MEDIUM5.4Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System Configuration page where the...
CVE-2026-45055HIGH8.1CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the...
CVE-2026-45054MEDIUM4.9CubeCart is an ecommerce software solution. Prior to 6.7.0, the admin orders-transactions listing page (admin.php?_g=ord...
CVE-2026-45053CRITICAL9.1CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists ...
CVE-2026-44418HIGH8.7EcclesiaCRM is CRM Software for church management. In 8.0.0 and earlier, the ValidateInput() function's default case in ...
CVE-2026-44381MEDIUM5.3MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed ...
CVE-2026-44380HIGH7.2MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerabili...
CVE-2026-44379MEDIUM5.3MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, MISP Collections did not enforce RFC 4...
CVE-2026-44377CRITICAL9.1CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulne...
CVE-2026-44376MEDIUM6.1CubeCart is an ecommerce software solution. Prior to 6.7.0, an unauthenticated Reflected XSS vulnerability exists in the...
CVE-2026-44373MEDIUM5.3Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by send...
CVE-2026-44372MEDIUM6.1Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could turn a redirect route rule using ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now