2026 CVE Vulnerabilities

66,658 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33616HIGH7.5An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection vulnerability in the mb24api endpo...
CVE-2026-33615CRITICAL9.1An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint du...
CVE-2026-33614HIGH7.5An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getinfo endpoint du...
CVE-2026-33613HIGH8.8Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an RCE vulne...
CVE-2026-29144MEDIUM5.3SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge security...
CVE-2026-29143CRITICAL9.1SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted...
CVE-2026-29142MEDIUM5.3SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to forge a GINA-encrypted email.
CVE-2026-29141MEDIUM5.3SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags suc...
CVE-2026-29140MEDIUM5.3SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker-controlled certificates to be u...
CVE-2026-29139CRITICAL9.8SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to re...
CVE-2026-29138HIGH7.5SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to claim ano...
CVE-2026-29137MEDIUM5.3SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to hide security tags from users by crafting a lo...
CVE-2026-29136MEDIUM6.1SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to inject HTML into notification emails about new...
CVE-2026-29135HIGH7.5SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to craft a password-tag that bypasses subject san...
CVE-2026-29134HIGH7.5SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass...
CVE-2026-29133CRITICAL9.1SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match th...
CVE-2026-29132HIGH7.5SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker with access to a victim's GINA account to bypass ...
CVE-2026-29131HIGH7.5SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to read the ...
CVE-2026-0634HIGH7.8Code execution in AssistFeedbackService of TECNO Pova7 Pro 5G on Android allows local apps to execute arbitrary code as ...
CVE-2026-5244CRITICAL9.8A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mo...
CVE-2026-5032HIGH7.5The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9....
CVE-2026-0688MEDIUM6.4The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5...
CVE-2026-0686HIGH7.2The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5...
CVE-2026-5325LOW3.5A vulnerability was determined in SourceCodester Simple Customer Relationship Management System 1.0. This issue affects ...
CVE-2026-5323MEDIUM5.3A vulnerability was found in priyankark a11y-mcp up to 1.0.5. This vulnerability affects the function A11yServer of the ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now