2026 CVE Vulnerabilities

65,007 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5358——Rejected reason: REJECTED: CVE-2026-5358 is rejected for two reasons. Firstly it has been discovered that no NIS+ client...
CVE-2026-4852MEDIUM6.4The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Stored Cross-Site ...
CVE-2026-34403HIGH8.1Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui u...
CVE-2026-33626HIGH7.5LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Ser...
CVE-2026-33432CRITICAL9.1Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8...
CVE-2026-33431MEDIUM6.5Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the POS...
CVE-2026-33031HIGH8.1Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an adminis...
CVE-2026-32613CRITICAL9.9Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring ...
CVE-2026-32604CRITICAL9.9Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2...
CVE-2026-29648HIGH8.8In OpenXiangShan NEMU, when Smstateen is enabled, clearing mstateen0.ENVCFG does not correctly restrict access to henvcf...
CVE-2026-29647MEDIUM6.5In OpenXiangShan NEMU, insufficient Smstateen permission enforcement allows lower-privileged code to access IMSIC state ...
CVE-2026-29646CRITICAL9.8In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to t...
CVE-2026-29642HIGH7.8A local attacker who can execute privileged CSR operations (or can induce firmware to do so) performs carefully crafted ...
CVE-2026-6550MEDIUM5.7Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and ...
CVE-2026-6257CRITICAL9.2Vvveb CMS v1.0.8.2 contains a remote code execution vulnerability in its media management functionality where a missing ...
CVE-2026-6249HIGH8.8Vvveb CMS 1.0.8.2 contains a remote code execution vulnerability in its media upload handler that allows authenticated a...
CVE-2026-5478HIGH8.1The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and incl...
CVE-2026-32311CRITICAL9.8Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri...
CVE-2026-32135HIGH7.5NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.11 have a remotely triggera...
CVE-2026-29649CRITICAL9.8NEMU contains an implementation flaw in its RISC-V Hypervisor CSR handling where henvcfg[7:4] (CBIE/CBCFE/CBZE-related f...
CVE-2026-29645HIGH7.5NEMU (OpenXiangShan/NEMU) before v2025.12.r2 contains an improper instruction-validation flaw in its RISC-V Vector (RVV)...
CVE-2026-6248HIGH8.1The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. Th...
CVE-2026-6060MEDIUM4.5A vulnerability in the SQL Box in the admin interface of OTRS leads to an uncontrolled resource consumption leading to a...
CVE-2026-41389MEDIUM6.3OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing ...
CVE-2026-39112MEDIUM5.4Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now