2026 CVE Vulnerabilities

64,824 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41656MEDIUM4.5Admidio is an open-source user management solution. Prior to version 5.0.9, the add mode in modules/documents-files.php ...
CVE-2026-41655MEDIUM6.5Admidio is an open-source user management solution. Prior to version 5.0.9, the ecard_preview.php endpoint does not vali...
CVE-2026-41640HIGH8.8NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t...
CVE-2026-41587HIGH8.6CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-41203CRITICAL9.4CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-41202CRITICAL9.4CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-41201CRITICAL9.1CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-41142HIGH8.8OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-41004MEDIUM4.4When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Sp...
CVE-2026-41002HIGH8.1The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git reposi...
CVE-2026-40982CRITICAL9.1Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server ...
CVE-2026-40981HIGH7.5When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the co...
CVE-2026-40004HIGH7.8There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execut...
CVE-2026-4807MEDIUM6.5The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and inclu...
CVE-2026-44600MEDIUM5.3Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-202...
CVE-2026-44599MEDIUM5.3Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.
CVE-2026-6222MEDIUM5.3The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1....
CVE-2026-40003MEDIUM6.8ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the l...
CVE-2026-44597CRITICAL9.1Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload,...
CVE-2026-6278——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-41484MEDIUM5.9OpenTelemetry.Exporter.OneCollector is a .NET exporter that sends telemetry to a OneCollector back-end over HTTP. In ver...
CVE-2026-41483MEDIUM5.9OpenTelemetry.Resources.Azure is the .NET resource detector for Azure environments. In versions 1.15.0-beta.1 and earlie...
CVE-2026-41417MEDIUM5.3Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created f...
CVE-2026-41310MEDIUM5.3OpenTelemetry.Exporter.Zipkin is the .NET Zipkin exporter for OpenTelemetry. In versions 1.15.2 and earlier, the Zipkin ...
CVE-2026-40296MEDIUM5.4PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The HTML writer skips htmlspecialchars e...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now