2026 CVE Vulnerabilities

64,803 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6213CRITICAL10A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check an...
CVE-2026-5341MEDIUM6.4The NMR Strava activities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `strava_nmr...
CVE-2026-7330HIGH7.2The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ...
CVE-2026-5127HIGH8.8The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP...
CVE-2026-44928MEDIUM5.3In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.
CVE-2026-44927MEDIUM5.3In uriparser before 1.0.2, there is pointer difference truncation to int in various places.
CVE-2026-43284HIGH8.8In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb fra...
CVE-2026-8149MEDIUM5.1A vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on X86_64, AVX, AVX-512f, Linux, Legion of the ...
CVE-2026-8069HIGH7.8PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes ...
CVE-2026-4935HIGH8.6The OttoKit: All-in-One Automation Platform WordPress plugin before 1.1.23 does not properly sanitize user input before ...
CVE-2026-44916LOW3In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered wit...
CVE-2026-8148HIGH7.8NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM...
CVE-2026-8138HIGH8.8A vulnerability was found in Tenda CX12L 16.03.53.12. This issue affects the function formSetPPTPServer of the file /gof...
CVE-2026-8137HIGH8.8A vulnerability has been found in Totolink X5000R 9.1.0u.6369_B20230113. This vulnerability affects the function sub_458...
CVE-2026-42279MEDIUM5.8solidtime is an open-source time-tracking app. In version 0.12.0, the PUT /api/v1/organizations/{organization}/time-entr...
CVE-2026-42278HIGH8.8UltraDAG is a minimal DAG-BFT blockchain in Rust. Prior to commit fb6ef59, the UltraDAG StateEngine implementation of Sm...
CVE-2026-42277MEDIUM6.5Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the GET /chat/file/{file_id} endpoint all...
CVE-2026-42276MEDIUM4.3Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the POST /chat/stop-chat-session/{chat_se...
CVE-2026-8136LOW2.4A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the fil...
CVE-2026-8133HIGH7.3A security vulnerability has been detected in zyx0814 FilePress up to 2.2.0. Affected by this vulnerability is an unknow...
CVE-2026-8132HIGH7.3A weakness has been identified in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /lo...
CVE-2026-8131HIGH7.3A security flaw has been discovered in SourceCodester SUP Online Shopping 1.0. This impacts an unknown function of the f...
CVE-2026-8130HIGH7.3A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. This affects an unknown function of the file /...
CVE-2026-8129HIGH7.3A vulnerability was determined in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of...
CVE-2026-44298MEDIUM4.9Kimai is an open-source time tracking application. From version 2.32.0 to before version 2.56.0, users with the role Sys...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now