2026 CVE Vulnerabilities

65,056 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40515MEDIUM5.5OpenHarness before commit bd4df81 contains a permission bypass vulnerability that allows attackers to read sensitive fil...
CVE-2026-3464HIGH8.8The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file pat...
CVE-2026-21733HIGH7.3Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to re...
CVE-2026-6497MEDIUM6.3A vulnerability was determined in prasathmani TinyFileManager up to 2.6. Affected by this vulnerability is an unknown fu...
CVE-2026-6284CRITICAL9.3An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to syst...
CVE-2026-21709MEDIUM6.7A vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement.
CVE-2026-6496MEDIUM5.4A vulnerability was found in prasathmani TinyFileManager up to 2.6. Affected is an unknown function of the file /fileman...
CVE-2026-6493LOW3.5A flaw has been found in lukevella rallly up to 4.7.4. This affects an unknown function of the file apps/web/src/app/[lo...
CVE-2026-41153CRITICAL9.8In JetBrains Junie before 252.549.29 command execution was possible via malicious project file
CVE-2026-37749CRITICAL9.8A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attack...
CVE-2026-6492MEDIUM5.5A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea....
CVE-2026-6491MEDIUM5.3A security vulnerability has been detected in libvips up to 8.18.2. The affected element is the function im_minpos_vec o...
CVE-2026-6490HIGH7.3A weakness has been identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. Impacted is an unknown f...
CVE-2026-40459HIGH8.8PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP synt...
CVE-2026-40458MEDIUM6.5PAC4J is vulnerable to Cross-Site Request Forgery (CSRF). A malicious attacker can craft a specially designed website wh...
CVE-2026-31317HIGH7.5Craftql v1.3.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitr...
CVE-2026-6507HIGH7.5A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially...
CVE-2026-6489MEDIUM6.3A security flaw has been discovered in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This issue affects ...
CVE-2026-6488MEDIUM6.3A vulnerability was identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This vulnerability affec...
CVE-2026-6487MEDIUM4.3A flaw has been found in Qihui jtbc5 CMS 5.0.3.6. Affected is an unknown function of the file /dev/code/common/diplomat/...
CVE-2026-6486LOW3.5A vulnerability was detected in classroombookings up to 2.17.0. This impacts the function read of the file crbs-core/app...
CVE-2026-28263MEDIUM4.8Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,...
CVE-2026-23777MEDIUM6.5Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,...
CVE-2026-6483HIGH7.3A vulnerability was found in Wavlink WL-WN530H4 20220721. This vulnerability affects the function strcat/snprintf of the...
CVE-2026-5131MEDIUM6.9GREENmod uses named pipes for communication between plugins, the web portal, and the system service, but the access cont...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now