2026 CVE Vulnerabilities

45,099 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-57389HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Adrian Tobey Groundhogg ...
CVE-2026-57388HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Boo...
CVE-2026-57387HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in picu picu picu all...
CVE-2026-57386HIGH8.8Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affec...
CVE-2026-57385HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appsbd Vitepos vit...
CVE-2026-57383HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch w...
CVE-2026-57382HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mitchell Bennis Si...
CVE-2026-57381HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive Prop...
CVE-2026-57380HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hupe13 Extensions ...
CVE-2026-57379HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat s...
CVE-2026-57378HIGH7.5Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting Incorrectly Configured...
CVE-2026-57376HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader El...
CVE-2026-57372HIGH7.2Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server Side Request Forgery....
CVE-2026-57371HIGH8.8Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue a...
CVE-2026-57369HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify ...
CVE-2026-57368HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonste...
CVE-2026-57363HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatB...
CVE-2026-22100HIGH8.6The OCPP DataTransfer message `ReserveLogin` is vulnerable to command injection. By manipulating the data value, arbitra...
CVE-2026-22099HIGH8.7The charging station does not require authentication for Bluetooth commands to perform actions. The functionality expose...
CVE-2026-15557HIGH7.3A weakness has been identified in waooAI waoowaoo up to 0.4.1. Affected by this vulnerability is the function getInterna...
CVE-2026-15548HIGH8.8A security vulnerability has been detected in Shibby Tomato up to 1.28.0000. This vulnerability affects the function sub...
CVE-2026-62143HIGH8.3A Server-Side Request Forgery (SSRF) protection bypass existed in the html_to_markdown expansion module of misp-modules....
CVE-2026-15574HIGH7.5A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorizat...
CVE-2026-15545HIGH8.8A vulnerability was identified in Shibby Tomato up to 1.28.0000. Affected by this vulnerability is the function main of ...
CVE-2026-15544HIGH8.8A vulnerability was determined in Shibby Tomato up to 1.28.0000. Affected is the function getupsvar of the file www/apcu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now