2026 CVE Vulnerabilities

64,848 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41471HIGH8.2The Easy PayPal Events & Tickets plugin for WordPress before version 1.4 contains an information disclosure vulnerabilit...
CVE-2026-37459HIGH7.5An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) v...
CVE-2026-32834HIGH8.7Easy PayPal Events & Tickets plugin for WordPress before version 1.4 contains a hardcoded authentication bypass vulnerab...
CVE-2026-2828——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-29004HIGH8.1BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS o...
CVE-2026-0073HIGH8.8In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic err...
CVE-2026-42812CRITICAL9.9In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table ...
CVE-2026-42811CRITICAL9.9In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, bu...
CVE-2026-42810CRITICAL9.9Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access pol...
CVE-2026-42809CRITICAL9.9Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effectiv...
CVE-2026-42440HIGH7.5OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader  Versions Affected:  before...
CVE-2026-42376CRITICAL9.8D-Link DIR-456U Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet...
CVE-2026-42375HIGH8.8D-Link DIR-600L Hardware Revision A1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daem...
CVE-2026-42374HIGH8.8D-Link DIR-600L Hardware Revision B1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daem...
CVE-2026-42373HIGH8.8D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet...
CVE-2026-42372HIGH8.8D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet...
CVE-2026-42090CRITICAL9.6Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and ...
CVE-2026-42080MEDIUM4.6PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, there is an arbitrary fi...
CVE-2026-42079HIGH8.6PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable t...
CVE-2026-42078MEDIUM4.6PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable t...
CVE-2026-42077MEDIUM5.2Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a prototype pollution vulnerabilit...
CVE-2026-42076CRITICAL9.8Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a command injection vulnerability ...
CVE-2026-42075HIGH8.1Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a path traversal vulnerability in ...
CVE-2026-42027CRITICAL9.8Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5,...
CVE-2026-40682CRITICAL9.1XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affec...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now