2026 CVE Vulnerabilities

65,619 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-39410MEDIUM4.8Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a discrepancy be...
CVE-2026-39409MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() ...
CVE-2026-39408HIGH7.5Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal...
CVE-2026-39407MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path handling ...
CVE-2026-39406MEDIUM5.3@hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in ser...
CVE-2026-39394CRITICAL9.8CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-39393HIGH8.1CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-39392MEDIUM4.8CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-39391MEDIUM4.8CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-39390MEDIUM4.8CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-39389HIGH7.2CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-5795HIGH7.4In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. ...
CVE-2026-35023MEDIUM5.3Wimi Teamwork On-Premises versions prior to 8.2.0 contain an insecure direct object reference vulnerability in the previ...
CVE-2026-31411MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: atm: fix crash due to unvalidated vcc pointer ...
CVE-2026-2509MEDIUM6.4The Page Builder: Pagelayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget's Cu...
CVE-2026-5600MEDIUM4.3A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact...
CVE-2026-5302HIGH8.1CORS misconfiguration in CoolerControl/coolercontrold <4.0.0 allows unauthenticated remote attackers to read data and se...
CVE-2026-5301MEDIUM6.1Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated attackers to take over the serv...
CVE-2026-5300CRITICAL9.1Unauthenticated functionality in CoolerControl/coolercontrold <4.0.0 allows unauthenticated attackers to view and modif...
CVE-2026-4402——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-28261MEDIUM5.5Dell Elastic Cloud Storage, version 3.8.1.7 and prior, and Dell ObjectScale, versions prior to 4.1.0.3 and version 4.2.0...
CVE-2026-27102HIGH7.8Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.1, contains an incorrect p...
CVE-2026-24511MEDIUM4.4Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.0, contains a generation o...
CVE-2026-5208HIGH7.2Command injection in alerts in CoolerControl/coolercontrold <4.0.0 allows authenticated attackers to execute arbitrary c...
CVE-2026-3396HIGH7.5WCAPF – WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL Injection via the 'post-author' parameter...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now