2026 CVE Vulnerabilities

64,848 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34956MEDIUM5.9A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the users...
CVE-2026-34002CRITICAL9.1A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension...
CVE-2026-34000CRITICAL9.1A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifical...
CVE-2026-32689HIGH8.7Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix allows a denial of servic...
CVE-2026-31196HIGH8.8OS command injection vulnerability in the traceroute diagnostic handler in /bin/httpd_clientside in ALTICE LABS / SFR Fr...
CVE-2026-31195HIGH8.8OS command injection vulnerability in the ping diagnostic handler in /bin/httpd_clientside in ALTICE LABS / SFR France G...
CVE-2026-7834CRITICAL9.8A security vulnerability has been detected in EFM ipTIME NAS1dual 1.5.24. This issue affects the function get_csrf_white...
CVE-2026-7778MEDIUM5An issue that could allow a dashboard configuration to be viewed from outside of the authorized organization scope has b...
CVE-2026-4304HIGH7.5The WeePie Cookie Allow plugin for WordPress is vulnerable to SQL Injection via the 'consent' parameter in all versions ...
CVE-2026-36356CRITICAL9.1The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthentica...
CVE-2026-36355HIGH7.7The rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3.4.14B) does not perfo...
CVE-2026-34408CRITICAL9.1An issue was discovered in Gambio 4.9.2.0 (patched in 2024-02 v1.0.0 for GX4 v4.0.0.0 to v4.9.2.0). The password reset f...
CVE-2026-29168HIGH7.3Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response dat...
CVE-2026-7833HIGH7.3A weakness has been identified in EFM ipTIME C200 up to 1.092. This vulnerability affects the function sub_408F90 of the...
CVE-2026-7832HIGH7A security flaw has been discovered in IObit Advanced SystemCare 19. This affects an unknown part of the file ASC.exe of...
CVE-2026-6918HIGH7.5In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte c...
CVE-2026-30246MEDIUM6.5Fiber is a web framework for Go. In github.com/gofiber/fiber/v3 versions through 3.1.0, the default key generator in the...
CVE-2026-28510MEDIUM5.9eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably pr...
CVE-2026-27694MEDIUM5.4Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the ema...
CVE-2026-27693MEDIUM5.4Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the KML...
CVE-2026-27644MEDIUM6.5Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality write...
CVE-2026-6262MEDIUM6.5The Betheme theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 28.4. This is...
CVE-2026-6261HIGH8.8The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is d...
CVE-2026-43574MEDIUM6.5OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolve...
CVE-2026-43573HIGH7.7OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now