2026 CVE Vulnerabilities

64,803 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4348HIGH7.5The BetterDocs Pro plugin for WordPress is vulnerable to SQL Injection via the `get_current_letter_docs` and `docs_sort_...
CVE-2026-41641HIGH7.2NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t...
CVE-2026-41586CRITICAL9.8Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applica...
CVE-2026-41413HIGH7.7Istio is an open platform to connect, manage, and secure microservices. Prior to versions 1.28.6 and 1.29.2, when a Requ...
CVE-2026-41143HIGH8.8YesWiki is a wiki system written in PHP. Prior to version 4.6.1, YesWiki bazar module contains a SQL injection vulnerabi...
CVE-2026-41139HIGH8.8Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary...
CVE-2026-6214MEDIUM6.5The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0....
CVE-2026-44603CRITICAL9.1Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.
CVE-2026-44602HIGH7.5Tor before 0.4.9.7 has a NULL pointer dereference when a CERT cell is received out of order, aka TROVE-2026-006.
CVE-2026-44601HIGH7.5Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close o...
CVE-2026-42217CRITICAL9.8OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-42216CRITICAL9.1OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-42194MEDIUM6.8Admidio is an open-source user management solution. Prior to version 5.0.9, the incomplete SSRF fix in Admidio's fetch_m...
CVE-2026-41891MEDIUM5.3CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-41890MEDIUM6.9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-41675HIGH7.5xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom...
CVE-2026-41674HIGH7.5xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom...
CVE-2026-41673HIGH7.5xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom...
CVE-2026-41672HIGH7.5xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom...
CVE-2026-41671MEDIUM6.8Admidio is an open-source user management solution. Prior to version 5.0.9, the OIDC token introspection endpoint (/modu...
CVE-2026-41670HIGH8.2Admidio is an open-source user management solution. Prior to version 5.0.9, the SAML IdP implementation in Admidio's SSO...
CVE-2026-41669HIGH8.2Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio SAML Identity Provider implement...
CVE-2026-41663LOW3.5Admidio is an open-source user management solution. Prior to version 5.0.9, several administrative operations in Admidio...
CVE-2026-41662MEDIUM5.2Admidio is an open-source user management solution. Prior to version 5.0.9, Role::stopMembership() does not verify wheth...
CVE-2026-41661MEDIUM6.1Admidio is an open-source user management solution. Prior to version 5.0.9, an unauthenticated attacker can execute arbi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now