2026 CVE Vulnerabilities

64,952 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41238MEDIUM6.9DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulne...
CVE-2026-40472CRITICAL9.9In hackage-server, user-controlled metadata from .cabal files are rendered into HTML href attributes without proper sani...
CVE-2026-40471CRITICAL9.6hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could ...
CVE-2026-40470CRITICAL9.9A critical XSS vulnerability affected hackage-server and hackage.haskell.org. HTML and JavaScript files provided in sou...
CVE-2026-39087MEDIUM6.4ntfy before 2.22.0 allows SSRF because of an unanchored regular expression for web push endpoint URLs.
CVE-2026-34003HIGH7.8A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially craft...
CVE-2026-34001HIGH7.8A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, sp...
CVE-2026-33999HIGH7.8A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map ...
CVE-2026-23751CRITICAL9.8Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecate...
CVE-2026-41461HIGH8.5SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the /core/link/previe...
CVE-2026-41460CRITICAL9.8SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoin...
CVE-2026-35225HIGH8.7An unauthenticated remote attacker is able to exhaust all available TCP connections in the CODESYS EtherNet/IP adapter s...
CVE-2026-39440CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFormsPro allows Remote ...
CVE-2026-31532HIGH7.8In the Linux kernel, the following vulnerability has been resolved: can: raw: fix ro->uniq use-after-free in raw_rcv() ...
CVE-2026-31531MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ipv4: nexthop: allocate skb dynamically in rtm_get_...
CVE-2026-28040MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Ta...
CVE-2026-6903HIGH8.7The LabOne Web Server, backing the LabOne User Interface, contains insufficient input validation in its file access func...
CVE-2026-6887CRITICAL9.8Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a SQL Injection vulnerability, allowing...
CVE-2026-6886CRITICAL9.8Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability, ...
CVE-2026-6885CRITICAL9.8Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File Upload vulnerability,...
CVE-2026-5464HIGH7.2The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to...
CVE-2026-3960CRITICAL9.8A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O...
CVE-2026-3259HIGH7.1A Generation of Error Message Containing Sensitive Information vulnerability in the Materialized View Refresh mechanism ...
CVE-2026-41564HIGH7.5CryptX versions before 0.088 for Perl do not reseed the Crypt::PK PRNG state after forking. The Crypt::PK::RSA, Crypt::...
CVE-2026-4512LOW3.5The reCaptcha by WebDesignBy WordPress plugin before 2.0 does not sanitize or escape the Site Key setting before outputt...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now