2026 CVE Vulnerabilities

64,760 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-4638HIGH7.1PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Script sensor that multiplies two integer parameters ...
CVE-2026-57590HIGH8.1A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not...
CVE-2026-97185HIGH7.8A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly ...
CVE-2026-85682HIGH8.8The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10....
CVE-2026-78311HIGH8.8SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-78309HIGH8.8SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-77193HIGH7.5The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and ...
CVE-2026-82077HIGH7.3An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax compone...
CVE-2026-88843HIGH7.2The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings...
CVE-2026-80513HIGH7.5The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes ...
CVE-2026-14780HIGH7.5A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization ...
CVE-2026-97152HIGH8.6Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport...
CVE-2026-97151HIGH8.4mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a documen...
CVE-2026-96898HIGH7.3A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected by this vulnerability is an unknown functionality...
CVE-2026-97055HIGH8.1SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOK...
CVE-2026-96803HIGH7.3A vulnerability was identified in java110 MicroCommunity up to 2.0. Affected is the function QueryServiceSMOImpl.fallBac...
CVE-2026-96762HIGH7.3A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegmen...
CVE-2026-96751HIGH7.3A vulnerability has been found in pmTicket Project-Management-Software up to 078fa56a782490c5059a0814f84df27984f4d7e2. T...
CVE-2026-92470HIGH7.7GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 19.2.7, 19.3 before 19.3.3, and 19.4...
CVE-2026-82370HIGH8.6Unauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service permits network-adjacent attack...
CVE-2026-70125HIGH8.8Microsoft Office Outlook Remote Code Execution Vulnerability
CVE-2026-96604HIGH7.3A vulnerability was identified in SoftNews Media Group DataLife Engine 18.0. This affects the function strip_data of the...
CVE-2026-96603HIGH7.3A vulnerability has been found in Abdurrab5 online-makeup-store. Affected is the function confirm_logged_in/confirm_user...
CVE-2026-96602HIGH7.3A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file customerSignin.php ...
CVE-2026-96601HIGH7.3A vulnerability was detected in Abdurrab5 online-makeup-store. This affects an unknown function of the file index.php of...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now