2026 CVE Vulnerabilities

64,785 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34087HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation OATHAuth. This issue a...
CVE-2026-34086LOW2.1Vulnerability in Wikimedia Foundation AbuseFilter. This issue affects AbuseFilter: from * before 1.43.7, 1.44.4, 1.45.2...
CVE-2026-31247HIGH7.5Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse...
CVE-2026-31246MEDIUM6.5GPT-Pilot thru commit 0819827ce20346ef5f25b3fe29293cb448840565 (2025-09-03) contains a command injection vulnerability (...
CVE-2026-8290MEDIUM6.5A security flaw has been discovered in Open5GS up to 2.7.7. This issue affects the function smf_nsmf_handle_update_data_...
CVE-2026-8289MEDIUM6.5A vulnerability was identified in Open5GS up to 2.7.7. This vulnerability affects the function smf_nsmf_handle_update_da...
CVE-2026-4802HIGH8A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the h...
CVE-2026-8288MEDIUM6.5A vulnerability was determined in Open5GS up to 2.7.7. This affects the function gsm_handle_pdu_session_modification_qos...
CVE-2026-6956MEDIUM5.1ATutor is vulnerable to Reflected XSS in /install/install.php endpoint. An attacker can provide a specially crafted URL ...
CVE-2026-6909MEDIUM5.1ATutor is vulnerable to Reflected XSS in /install/upgrade.php endpoint. An attacker can provide a specially crafted URL ...
CVE-2026-41951HIGH8.6Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS te...
CVE-2026-40636HIGH7.8Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded c...
CVE-2026-35157CRITICAL9.8Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper neutraliz...
CVE-2026-32658HIGH8.8Dell Automation Platform versions prior to 2.0.0.0, contains a missing authorization vulnerability. A low privileged att...
CVE-2026-26946MEDIUM6.7Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper privilege...
CVE-2026-43826MEDIUM6.5The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:pa...
CVE-2026-41018MEDIUM6.5The Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user...
CVE-2026-5084MEDIUM6.5WebDyne::Session versions before 3.003_704 for Perl generate the session id insecurely. The session handler generates t...
CVE-2026-43500HIGH7.8In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when page...
CVE-2026-8276LOW3.7A flaw has been found in bettercap up to 2.41.5. Affected by this issue is some unknown functionality of the file module...
CVE-2026-8275LOW3.7A vulnerability was detected in bettercap up to 2.41.5. Affected by this vulnerability is the function ippReadChunkedBod...
CVE-2026-6433HIGH7.3The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL quer...
CVE-2026-1677MEDIUM5.3Zephyr sockets created with `IPPROTO_TLS_1_3` can still negotiate a TLS 1.2 connection when both TLS versions are enable...
CVE-2026-8274MEDIUM5.3A security vulnerability has been detected in npitre cramfs-tools up to 2.1. Affected is the function do_directory of th...
CVE-2026-8273HIGH7.2A weakness has been identified in D-Link DNS-320 2.06B01. This impacts the function cgi_set_host/cgi_set_ntp/cgi_fan_con...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now