2026 CVE Vulnerabilities

65,619 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-30814HIGH8A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attac...
CVE-2026-2942CRITICAL9.8The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati...
CVE-2026-27806HIGH7.8Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotati...
CVE-2026-20709MEDIUM6.6Use of Default Cryptographic Key in the hardware for some Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(...
CVE-2026-0814MEDIUM4.3The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi...
CVE-2026-0811MEDIUM5.4The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2026-33756HIGH7.5Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, Saleor supports query b...
CVE-2026-33466CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and po...
CVE-2026-33459MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)...
CVE-2026-33458HIGH7.7Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user w...
CVE-2026-32591MEDIUM5.5A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an u...
CVE-2026-32590HIGH8.8A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores interm...
CVE-2026-32589HIGH7.4A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any reposit...
CVE-2026-4837HIGH7.2An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically all...
CVE-2026-4498HIGH7.7Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index dat...
CVE-2026-33461MEDIUM6.5Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). A user w...
CVE-2026-33460MEDIUM4.3Incorrect Authorization (CWE-863) in Kibana can lead to cross-space information disclosure via Privilege Abuse (CAPEC-12...
CVE-2026-31017CRITICAL9.1A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frapp...
CVE-2026-30080HIGH7.5OpenAirInterface v2.2.0 accepts Security Mode Complete without any integrity protection. Configuration has supported int...
CVE-2026-30075HIGH7.5OpenAirInterface Version 2.2.0 has a Buffer Overflow vulnerability in processing UplinkNASTransport containing Authentic...
CVE-2026-2377MEDIUM6.5A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products all...
CVE-2026-33753HIGH7.5rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to 1.0.6, an ...
CVE-2026-33229CRITICAL9.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8...
CVE-2026-31040CRITICAL9.8A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-fil...
CVE-2026-39865MEDIUM5.9Axios is a promise based HTTP client for the browser and Node.js. Starting in version 1.13.0 and prior to 1.13.2, Axios ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now