2026 CVE Vulnerabilities

43,246 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-16230CRITICAL9.8The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path vali...
CVE-2026-13457HIGH7.5The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all ...
CVE-2026-73228MEDIUM5.3Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing ...
CVE-2026-73227HIGH8.1electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al...
CVE-2026-73226HIGH8.8electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm al...
CVE-2026-73225HIGH8.1electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al...
CVE-2026-73224HIGH8.8electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al...
CVE-2026-73223HIGH8.1electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al...
CVE-2026-73222HIGH8.8Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio ...
CVE-2026-73221MEDIUM5.3CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user...
CVE-2026-72742CRITICAL9.2DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attacke...
CVE-2026-69119HIGH8.3Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any aut...
CVE-2026-69117MEDIUM6.5NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only...
CVE-2026-69115HIGH7.1OpenIM Server v3.8.3 contains a missing authorization vulnerability that allows any authenticated user to access admin-o...
CVE-2026-48809HIGH7.5python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have tw...
CVE-2026-48802HIGH7.5python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an atta...
CVE-2026-18712HIGH8.1An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileg...
CVE-2026-18711HIGH7.1An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to ...
CVE-2026-18709MEDIUM6.4An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit ...
CVE-2026-18708MEDIUM6.4An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to caus...
CVE-2026-18707MEDIUM5.3An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the se...
CVE-2026-18706HIGH7.5An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation ...
CVE-2026-18705HIGH7.1An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view ...
CVE-2026-18704HIGH7.1An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perfor...
CVE-2026-18703MEDIUM4.2An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authe...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now