2026 CVE Vulnerabilities

67,274 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-88855HIGH8.6Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Jooml...
CVE-2026-88854CRITICAL9.3Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 ...
CVE-2026-94040MEDIUM5.3A flaw has been found in vas3k TaxHacker up to 0.8.5. Affected by this vulnerability is the function testLLMProviderActi...
CVE-2026-94039HIGH7.3A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoicePDF of the file /ap...
CVE-2026-94038HIGH7.3A security vulnerability has been detected in NonceGeek dim-sum-app. This impacts the function textSearchV2Handler of th...
CVE-2026-94037MEDIUM4.3A weakness has been identified in 00Kisumi00 mcp-file-analyzer up to 84740852f0cf0cf5db4781b1ca6d7c6a6d210405. This affe...
CVE-2026-94036HIGH8.8A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element i...
CVE-2026-94035MEDIUM4.3A vulnerability was determined in SourceCodester Drug Recommendation System 1.0. Impacted is an unknown function of the ...
CVE-2026-94034LOW3.5A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing o...
CVE-2026-94033LOW3.5A vulnerability has been found in SourceCodester Drug Recommendation System 1.0. This vulnerability affects unknown code...
CVE-2026-94032MEDIUM6.3A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown part of the file /module/depa...
CVE-2026-94031MEDIUM6.3A vulnerability was detected in 0-Gaurav-0 nexus-mcp aed0026e7ac1f23dc940e46e9fd3a2da6904f914. Affected by this issue is...
CVE-2026-94030LOW3.1A security vulnerability has been detected in SerenityOS up to 3d83e4509fd20d7438e1ae8470ffe668c136229c. Affected by thi...
CVE-2026-94028MEDIUM4.3A weakness has been identified in mealie-recipes Mealie up to 3.25.1. Affected is the function payload.model_dump of the...
CVE-2026-94016LOW2.4A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function o...
CVE-2026-94015HIGH7.3A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the...
CVE-2026-92254MEDIUM6.9Missing Authorization in the IOCTL handlers of the wsdkd.sys kernel drivers in Watchdog WatchDog Antivirus 1.8.640 (driv...
CVE-2026-92253MEDIUM5.2Improper link resolution before file access in the quarantine restoration process of WatchDog Anti-Virus 1.8.640 on Wind...
CVE-2026-92252MEDIUM5.9Incorrect default permissions in the installation directory of WatchDog Anti-Virus on Windows allow local, low-privilege...
CVE-2026-90817CRITICAL9.8An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import proce...
CVE-2026-94113MEDIUM6.5Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in white...
CVE-2026-94112MEDIUM6.8mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured ...
CVE-2026-94111MEDIUM6.6Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin ...
CVE-2026-94109HIGH8openEQUELLA before 2026.1.0 contains an authenticated stored server-side template injection vulnerability in FreemarkerP...
CVE-2026-94108MEDIUM6.5getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fail...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now