2026 CVE Vulnerabilities

64,840 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-23927MEDIUM6.5A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead ...
CVE-2026-23926MEDIUM6.8An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by...
CVE-2026-2306MEDIUM4.3The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation du...
CVE-2026-5753MEDIUM6.5The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions ...
CVE-2026-3208MEDIUM5.3The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a mis...
CVE-2026-7573HIGH7.7An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 a...
CVE-2026-7572MEDIUM5.5An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor befor...
CVE-2026-44405LOW3.4In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm.
CVE-2026-40934MEDIUM6.8Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign auth...
CVE-2026-40110HIGH7.3Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation...
CVE-2026-40075HIGH7.5OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8...
CVE-2026-28780CRITICAL9.8Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a maliciou...
CVE-2026-41950MEDIUM6.5Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the fu...
CVE-2026-40068HIGH8.8In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir f...
CVE-2026-39852HIGH8.2Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3...
CVE-2026-39849HIGH8.8Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1,...
CVE-2026-39402MEDIUM6.5lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_l...
CVE-2026-39383HIGH7.2Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access c...
CVE-2026-35579CRITICAL9.8CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementati...
CVE-2026-35527MEDIUM5Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues ...
CVE-2026-7857HIGH7.3A vulnerability has been found in D-Link DI-8100 16.07.26A1. This vulnerability affects the function sprintf of the file...
CVE-2026-7856HIGH7.3A flaw has been found in D-Link DI-8100 16.07.26A1. This affects an unknown part of the file /url_member.asp of the comp...
CVE-2026-44331HIGH8.1In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap...
CVE-2026-40331CRITICAL9.3Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 throu...
CVE-2026-40330CRITICAL9.3Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 throu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now