2026 CVE Vulnerabilities

65,724 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-23818CRITICAL9.6A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Pre...
CVE-2026-22679CRITICAL9.8Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability ...
CVE-2026-22666HIGH8.6Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_s...
CVE-2026-31842HIGH8.7Tinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization due to a case-sensitive comparison of t...
CVE-2026-4420MEDIUM5.4Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its page creating functionality. An authenticated attacker ...
CVE-2026-34904HIGH7.5Cross-Site Request Forgery (CSRF) vulnerability in Analytify Simple Social Media Share Buttons allows Cross Site Request...
CVE-2026-34903MEDIUM5.4Missing Authorization vulnerability in OceanWP Ocean Extra allows Exploiting Incorrectly Configured Access Control Secur...
CVE-2026-34899MEDIUM5.3Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – Worldwide Express Edition allows Exploiti...
CVE-2026-34896HIGH7.5Cross-Site Request Forgery (CSRF) vulnerability in Analytify Under Construction, Coming Soon & Maintenance Mode allows C...
CVE-2026-34197HIGH8.8Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Br...
CVE-2026-33227MEDIUM4.3Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ...
CVE-2026-28810LOW3.7Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows D...
CVE-2026-3177MEDIUM5.3The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vul...
CVE-2026-5465HIGH8.8The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object R...
CVE-2026-4079MEDIUM6.5The SQL Chart Builder WordPress plugin before 2.3.8 does not properly escape user input as it is concatened to SQL queri...
CVE-2026-1900MEDIUM6.5The Link Whisper Free WordPress plugin before 0.9.1 has a publicly accessible REST endpoint that allows unauthenticated ...
CVE-2026-1114CRITICAL9.8In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to t...
CVE-2026-1839HIGH7.8A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code ...
CVE-2026-0740CRITICAL9.8The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val...
CVE-2026-20446MEDIUM4.3In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of serv...
CVE-2026-20433HIGH8.8In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of...
CVE-2026-20432HIGH8In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of...
CVE-2026-20431MEDIUM6.5In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE ha...
CVE-2026-5719MEDIUM6.3A flaw has been found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /...
CVE-2026-5705MEDIUM4.3A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown f...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now