2026 CVE Vulnerabilities

64,952 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-38743MEDIUM4.3The authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and Task...
CVE-2026-21515CRITICAL9.9Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate...
CVE-2026-6043HIGH8.8P4 Server versions prior to 2026.1 are configured with insecure default settings that, when exposed to untrusted network...
CVE-2026-4313LOW2.4AdaptiveGRC is vulnerable to Stored XSS via text type fields across the forms. Authenticated attacker can replace the va...
CVE-2026-23902HIGH8.1Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permission...
CVE-2026-41044HIGH8.8Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, A...
CVE-2026-41043MEDIUM6.5Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache A...
CVE-2026-40466HIGH8.8Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Br...
CVE-2026-6272HIGH8.5A client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v...
CVE-2026-21728HIGH7.5Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, dep...
CVE-2026-4078MEDIUM6.4The ITERAS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes (iteras-ordering, i...
CVE-2026-3569MEDIUM5.3The Liaison Site Prober plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 1...
CVE-2026-3565MEDIUM4.3The Taqnix plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3....
CVE-2026-1952HIGH7.5Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability.
CVE-2026-1951CRITICAL9.8Delta Electronics AS320T has no checking of the length of the buffer with the directory name vulnerability.
CVE-2026-1950CRITICAL9.8Delta Electronics AS320T has No checking of the length of the buffer with the file name vulnerability.
CVE-2026-6810MEDIUM5.3The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions...
CVE-2026-5428MEDIUM6.4The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the I...
CVE-2026-5364HIGH8.1The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions...
CVE-2026-5347MEDIUM5.3The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.8.0. ...
CVE-2026-1949CRITICAL9.8Delta Electronics AS320T has incorrect calculation of the buffer size on the stack in the GET/PUT request handler of the...
CVE-2026-6947HIGH8.7DWM-222W USB Wi-Fi Adapter developed by D-Link has a Brute-Force Protection Bypass vulnerability, allowing unauthenticat...
CVE-2026-6393MEDIUM4.3The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.3.11. This ...
CVE-2026-5488MEDIUM5.3The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization ...
CVE-2026-41485HIGH7.7Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.17.2 and 1.16.4, an...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now