2026 CVE Vulnerabilities

67,045 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34042HIGH8.2act is a project which allows for local running of github actions. Prior to version 0.2.86, act's built in actions/cache...
CVE-2026-34041CRITICAL9.8act is a project which allows for local running of github actions. Prior to version 0.2.86, act unconditionally processe...
CVE-2026-34040HIGH7.8Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that all...
CVE-2026-34036MEDIUM6.5Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versio...
CVE-2026-33997HIGH8.1Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that all...
CVE-2026-32727MEDIUM6.5SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.7, the Enforcer is vulnerable ...
CVE-2026-32716MEDIUM6.5SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the Enforcer incorrectly va...
CVE-2026-32714CRITICAL9.8SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scito...
CVE-2026-5176CRITICAL9.8A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. Affected is the function setSyslogCfg of ...
CVE-2026-4020HIGH7.5The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi...
CVE-2026-3300CRITICAL9.8The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions...
CVE-2026-5115HIGH7.5The PaperCut NG/MF (specifically, the embedded application for Konica Minolta devices) is vulnerable to session hijackin...
CVE-2026-4794MEDIUM4.8Multiple cross-site scripting (XSS) vulnerabilities in PaperCut NG/MF before 25.0.10 allow authenticated administrator u...
CVE-2026-32734MEDIUM6.1baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has DOM-based cross-site scripting in tag ...
CVE-2026-30940HIGH7.2baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme ...
CVE-2026-30880CRITICAL9.8baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability ...
CVE-2026-30879MEDIUM6.1baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a cross-site scripting vulnerability i...
CVE-2026-30878MEDIUM5.3baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API allows unauthenticated...
CVE-2026-30877HIGH7.2baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in t...
CVE-2026-27697CRITICAL9.8baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a SQL injection vulnerability in blog ...
CVE-2026-21861HIGH7.2baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerabi...
CVE-2026-5157MEDIUM4.3A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected is an unknown function of the ...
CVE-2026-5156HIGH8.8A vulnerability was determined in Tenda CH22 1.0.0.1. This impacts the function formQuickIndex of the file /goform/Quick...
CVE-2026-5155HIGH8.8A vulnerability was found in Tenda CH22 1.0.0.1. This affects the function fromAdvSetWan of the file /goform/AdvSetWan o...
CVE-2026-5154HIGH8.8A vulnerability has been found in Tenda CH22 1.0.0.1/1.If. The impacted element is the function fromSetCfm of the file /...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now