2026 CVE Vulnerabilities

64,760 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-86583HIGH8.8The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up ...
CVE-2026-81537HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to...
CVE-2026-81536HIGH7.7IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information ...
CVE-2026-81208HIGH7.7IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to imp...
CVE-2026-80423HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information ...
CVE-2026-75887HIGH7.5A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by man...
CVE-2026-19125HIGH8.1The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includi...
CVE-2026-96556HIGH7.3A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerability is the function addcashier of the fi...
CVE-2026-82369HIGH8.6Insufficient input sanitization of shell metacharacters in the Brocade SANnav CLI scripting component permits authentica...
CVE-2026-80425HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du...
CVE-2026-80412HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to...
CVE-2026-80379HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du...
CVE-2026-75886HIGH7.2A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the Catalogd...
CVE-2026-6935HIGH7.8IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequatel...
CVE-2026-6794HIGH7.8IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management. A local ...
CVE-2026-67235HIGH7.1RabbitMQ is a messaging and streaming broker. Prior to versions 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15, The content-h...
CVE-2026-67232HIGH8.2RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The cowboy We...
CVE-2026-66077HIGH7.3RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6, The management UI us...
CVE-2026-96889HIGH7.8A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate...
CVE-2026-96826HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shazzad Hossain Kh...
CVE-2026-94183HIGH7.4Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen m...
CVE-2026-86065HIGH7.5Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /subscribe e...
CVE-2026-86064HIGH8.6Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSock...
CVE-2026-85475HIGH7.2A flaw was found in the Ansible Automation Platform automation controller. The external logging (rsyslog) configuration ...
CVE-2026-84714HIGH7.1A flaw was found in the automation-controller input-validation guard sanitize_jinja(). The function us...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now