2026 CVE Vulnerabilities

65,045 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-29642HIGH7.8A local attacker who can execute privileged CSR operations (or can induce firmware to do so) performs carefully crafted ...
CVE-2026-6550MEDIUM5.7Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and ...
CVE-2026-6257CRITICAL9.2Vvveb CMS v1.0.8.2 contains a remote code execution vulnerability in its media management functionality where a missing ...
CVE-2026-6249HIGH8.8Vvveb CMS 1.0.8.2 contains a remote code execution vulnerability in its media upload handler that allows authenticated a...
CVE-2026-5478HIGH8.1The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and incl...
CVE-2026-32311CRITICAL9.8Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri...
CVE-2026-32135HIGH7.5NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.11 have a remotely triggera...
CVE-2026-29649CRITICAL9.8NEMU contains an implementation flaw in its RISC-V Hypervisor CSR handling where henvcfg[7:4] (CBIE/CBCFE/CBZE-related f...
CVE-2026-29645HIGH7.5NEMU (OpenXiangShan/NEMU) before v2025.12.r2 contains an improper instruction-validation flaw in its RISC-V Vector (RVV)...
CVE-2026-6248HIGH8.1The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. Th...
CVE-2026-6060MEDIUM4.5A vulnerability in the SQL Box in the admin interface of OTRS leads to an uncontrolled resource consumption leading to a...
CVE-2026-41389MEDIUM6.3OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing ...
CVE-2026-39112MEDIUM5.4Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in ...
CVE-2026-39111HIGH7.5SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the ema...
CVE-2026-39110HIGH8.2SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the con...
CVE-2026-39109CRITICAL9.4SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the...
CVE-2026-26399MEDIUM5.3A stack-use-after-return issue exists in the Arduino_Core_STM32 library prior to version 1.7.0. The pwm_start() function...
CVE-2026-23758MEDIUM5.4GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows ...
CVE-2026-23757MEDIUM5.4GFI HelpDesk before 4.99.10 contains a stored cross-site scripting vulnerability in the Reports module where the title p...
CVE-2026-23756MEDIUM5.4GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the s...
CVE-2026-23753MEDIUM4.8GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the language management functionality...
CVE-2026-23752MEDIUM4.8GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the template group creation and editi...
CVE-2026-6662HIGH7.3A vulnerability was found in ericc-ch copilot-api up to 0.7.0. The impacted element is the function cors of the file src...
CVE-2026-41445HIGH8.8KissFFT before commit 8a8e66e contains an integer overflow vulnerability in the kiss_fftndr_alloc() function in kiss_fft...
CVE-2026-40488HIGH8.8Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now