2026 CVE Vulnerabilities

65,056 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-35153MEDIUM6.7Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers...
CVE-2026-35074MEDIUM6.7Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers...
CVE-2026-35073MEDIUM6.7Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers...
CVE-2026-35072MEDIUM6.7Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers...
CVE-2026-23779MEDIUM6.7Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,...
CVE-2026-23776HIGH8.8Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,...
CVE-2026-6494MEDIUM5.3A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by ...
CVE-2026-6439MEDIUM4.4The VideoZen plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.1. Th...
CVE-2026-23778HIGH7.2Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,...
CVE-2026-23775MEDIUM5.7Dell PowerProtect Data Domain appliances with Data Domain Operating System (DD OS) of Feature Release versions 8.0 throu...
CVE-2026-6451MEDIUM4.3The cms-fuer-motorrad-werkstaetten plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to an...
CVE-2026-40002HIGH8.8Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operatio...
CVE-2026-33392HIGH7.2In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass
CVE-2026-23853HIGH8.4Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,...
CVE-2026-6443CRITICAL9.8All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to ...
CVE-2026-6441MEDIUM4.3The Canto plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 3.1.1. This is due...
CVE-2026-4659HIGH7.5The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV...
CVE-2026-6482HIGH7.8The Rapid7 Insight Agent (versions > 4.1.0.2) is vulnerable to a local privilege escalation attack that allows users to ...
CVE-2026-6421HIGH7A vulnerability has been found in Mobatek MobaXterm Home Edition up to 26.1. This affects an unknown part in the library...
CVE-2026-5797MEDIUM5.3The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and inc...
CVE-2026-35496MEDIUM5.1A path traversal vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privileg...
CVE-2026-34018CRITICAL9.8An SQL injection vulnerability exists in CubeCart prior to 6.6.0, which may allow an attacker to execute an arbitrary SQ...
CVE-2026-21719HIGH8.6An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative p...
CVE-2026-6080MEDIUM6.5The Tutor LMS plugin for WordPress is vulnerable to SQL Injection in versions up to and including 3.9.8. This is due to ...
CVE-2026-5807HIGH7.5Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now