2026 CVE Vulnerabilities

65,045 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40098MEDIUM5.4Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun...
CVE-2026-35154MEDIUM6.7Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers...
CVE-2026-30269CRITICAL9.9Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a...
CVE-2026-30266HIGH7.8Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbit...
CVE-2026-28684MEDIUM6.6python-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, ...
CVE-2026-26951MEDIUM6.7Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r...
CVE-2026-26943HIGH7.2Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r...
CVE-2026-26942HIGH7.2Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used i...
CVE-2026-25525MEDIUM4.9Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun...
CVE-2026-25524HIGH8.1Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun...
CVE-2026-24506HIGH7.2Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r...
CVE-2026-24505HIGH7.2Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain an improper input validation vulnerability. A high privi...
CVE-2026-24504HIGH7.2Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r...
CVE-2026-22761HIGH7.2Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A high privileged att...
CVE-2026-6652MEDIUM4.7A weakness has been identified in Pagekit CMS up to 1.0.18. This issue affects the function evaluate of the file app/mod...
CVE-2026-6651LOW2.4A security flaw has been discovered in erponline.xyz ERP Online up to 4.0.0. This vulnerability affects unknown code of ...
CVE-2026-6650MEDIUM4.7A vulnerability was identified in Z-BlogPHP 1.7.5. This affects the function App::UnPack of the file /zb_users/plugin/Ap...
CVE-2026-6066HIGH7.1ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automa...
CVE-2026-41245HIGH7.5Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFold...
CVE-2026-40896HIGH7.1OpenProject is open-source, web-based project management software. Prior to version 17.3.0, a user with `manage_agendas`...
CVE-2026-3219MEDIUM4.6pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP f...
CVE-2026-39918CRITICAL9.8Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST parame...
CVE-2026-34429MEDIUM5.4Vvveb prior to 1.0.8.1 contains a stored cross-site scripting vulnerability that allows authenticated users with media u...
CVE-2026-34428HIGH8.3Vvveb prior to 1.0.8.1 contains a server-side request forgery vulnerability in the oEmbedProxy action of the editor/edit...
CVE-2026-34427HIGH8.8Vvveb prior to 1.0.8.1 contains a privilege escalation vulnerability in the admin user profile save endpoint that allows...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now