2026 CVE Vulnerabilities

65,056 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5426CRITICAL9.1Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 all...
CVE-2026-37100MEDIUM6.5An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App: ...
CVE-2026-6409HIGH7.1A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Malici...
CVE-2026-3324HIGH8.2Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due...
CVE-2026-37347CRITICAL9.1SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_e...
CVE-2026-37346MEDIUM4.7SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_a...
CVE-2026-37345CRITICAL9.8SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_pa...
CVE-2026-37344HIGH7.2SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_lo...
CVE-2026-37343HIGH7.2SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_us...
CVE-2026-37342HIGH7.2SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/view_park...
CVE-2026-37341HIGH7.2SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_ca...
CVE-2026-37340CRITICAL9.8SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php...
CVE-2026-37339CRITICAL9.8SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php...
CVE-2026-37338CRITICAL9.4SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php.
CVE-2026-37337HIGH7.3SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_playlist....
CVE-2026-37336HIGH7.3SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_music.php...
CVE-2026-33804CRITICAL9.1@fastify/middie versions 9.3.1 and earlier are vulnerable to middleware bypass when the deprecated Fastify ignoreDuplica...
CVE-2026-30656HIGH7.5A NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the...
CVE-2026-30459HIGH7.1An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the...
CVE-2026-2840MEDIUM6.4The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2026-6410MEDIUM5.3@fastify/static versions 8.0.0 through 9.1.0 allow path traversal when directory listing is enabled via the list option....
CVE-2026-6270CRITICAL9.1@fastify/middie versions 9.3.1 and earlier do not register inherited middleware directly on child plugin engine instance...
CVE-2026-5785HIGH8.1Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are ...
CVE-2026-4160MEDIUM5.3The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne...
CVE-2026-31987HIGH7.5JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to up...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now