2026 CVE Vulnerabilities

64,803 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8080MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows...
CVE-2026-6508CRITICAL9.8Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Acces...
CVE-2026-42285HIGH7.5GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.4.0, a...
CVE-2026-42010CRITICAL9.8A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched ...
CVE-2026-41644HIGH7.1monetr is a budgeting application for recurring expenses. Prior to version 1.12.5, a server-side request forgery (SSRF) ...
CVE-2026-41643HIGH7.5GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4....
CVE-2026-41642HIGH7.5GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a...
CVE-2026-3953HIGH8.8Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gosoft Software In...
CVE-2026-33589MEDIUM6.5Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to ac...
CVE-2026-33588HIGH8.1Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to cr...
CVE-2026-33587CRITICAL10Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subseque...
CVE-2026-28201HIGH7.8An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allo...
CVE-2026-27415MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in PluginUs.Net BEAR allows Cross Site Request Forgery. This issue affe...
CVE-2026-6805HIGH7.5Vulnerability on the external sharing feature in Cryptobox allows an attacker knowing a sharing link URL to retrieve inf...
CVE-2026-44407HIGH7.5A remote denial-of-service vulnerability exists in the ZTE Cloud PC client uSmartview, which may lead to memory corrupti...
CVE-2026-27421MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elem...
CVE-2026-27416MEDIUM5.3Missing Authorization vulnerability in bPlugins PDF Poster allows Exploiting Incorrectly Configured Access Control Secur...
CVE-2026-27329MEDIUM5.3Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Wishlist allows Exploiting Incor...
CVE-2026-25468MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs Happy Addons for Elem...
CVE-2026-25436MEDIUM5.3Missing Authorization vulnerability in WProyal Royal Elementor Addons allows Exploiting Incorrectly Configured Access Co...
CVE-2026-4430HIGH7.8Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched enc...
CVE-2026-44406HIGH7.8ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM...
CVE-2026-8063HIGH7.1An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view. When ...
CVE-2026-7252HIGH8.1The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress...
CVE-2026-6692HIGH8.8The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now