2026 CVE Vulnerabilities

65,063 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40719HIGH7.5Deadwood in MaraDNS 3.5.0036 allows attackers to exhaust connection slots via a zone whose authoritative nameserver addr...
CVE-2026-5160MEDIUM6.1Versions of the package github.com/yuin/goldmark/renderer/html before 1.7.17 are vulnerable to Cross-site Scripting (XSS...
CVE-2026-5397HIGH7.8It has been identified that a vulnerability (CWE-427) exists in the UPS (Uninterruptible Power Supply) management applic...
CVE-2026-26291MEDIUM5.4Stored cross-site scripting vulnerability exists in GROWI v7.4.6 and earlier. If this vulnerability is exploited, an arb...
CVE-2026-6328HIGH8.3Improper input validation, Improper verification of cryptographic signature vulnerability in XQUIC Project XQUIC xquic o...
CVE-2026-4812MEDIUM5.3The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disc...
CVE-2026-40499HIGH7.8radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function tha...
CVE-2026-40105MEDIUM6.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 10.4-r...
CVE-2026-40104HIGH8.2XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 1.8-rc...
CVE-2026-40096MEDIUM5.4immich is a high performance self-hosted photo and video management solution. Versions prior to 2.7.3 contain an open re...
CVE-2026-40091MEDIUM4.4SpiceDB is an open source database system for creating and managing security-critical application permissions. In versio...
CVE-2026-40090HIGH7.1Zarf is an Airgap Native Packager Manager for Kubernetes. Versions 0.23.0 through 0.74.1 contain an arbitrary file write...
CVE-2026-39984MEDIUM5.5Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authoriza...
CVE-2026-39971HIGH7.2Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the email sending functionality in include/...
CVE-2026-39963MEDIUM6.9Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the serendipity_setCookie() function in in...
CVE-2026-39884HIGH8.1mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Versions 3.4.0 and prior con...
CVE-2026-39842CRITICAL9.9OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulne...
CVE-2026-33806HIGH7.5Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypasse...
CVE-2026-2834HIGH7.2The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2026-2396MEDIUM4.4The List View Google Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event descriptio...
CVE-2026-1555CRITICAL9.8The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_i...
CVE-2026-1541MEDIUM4.3The Avada (Fusion) Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a...
CVE-2026-1509MEDIUM5.4The Avada (Fusion) Builder plugin for WordPress is vulnerable to Arbitrary WordPress Action Execution in all versions up...
CVE-2026-1314MEDIUM5.3The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to unauth...
CVE-2026-40688HIGH7.2An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now