2026 CVE Vulnerabilities

67,045 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5130HIGH8.8The Debugger & Troubleshooter plugin for WordPress was vulnerable to Unauthenticated Privilege Escalation in versions up...
CVE-2026-5153HIGH8.8A flaw has been found in Tenda CH22 1.0.0.1. The affected element is the function FormWriteFacMac of the file /goform/Wr...
CVE-2026-4257CRITICAL9.8The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Rem...
CVE-2026-33995MEDIUM5.3FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a double-free vulnerability in...
CVE-2026-33987MEDIUM6.6FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in persistent_cache_read_entry...
CVE-2026-33986HIGH7.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in yuv_ensure_buffer() in libf...
CVE-2026-33985HIGH7.1FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap ...
CVE-2026-33984HIGH7.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libf...
CVE-2026-33983MEDIUM6.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, progressive_decompress_tile_up...
CVE-2026-33982HIGH8.1FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, there is a heap-buffer-overflo...
CVE-2026-33977MEDIUM6.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a malicious RDP server can cra...
CVE-2026-33952MEDIUM6.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, an unvalidated auth_length fie...
CVE-2026-32794MEDIUM4.8Improper Certificate Validation vulnerability in Apache Airflow Provider for Databricks. Provider code did not validate ...
CVE-2026-5152HIGH8.8A vulnerability was detected in Tenda CH22 1.0.0.1. Impacted is the function formCreateFileName of the file /goform/crea...
CVE-2026-4789CRITICAL9.8Kyverno, versions 1.16.0 and later, are vulnerable to SSRF due to unrestricted CEL HTTP functions.
CVE-2026-34558CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-34557CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-32884MEDIUM5.9Botan is a C++ cryptography library. Prior to version 3.11.0, during processing of an X.509 certificate path using name ...
CVE-2026-32883MEDIUM5.9Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP resp...
CVE-2026-32877HIGH8.2Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0, during SM2 decryption, the code that c...
CVE-2026-32696HIGH7.5NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In NanoMQ version 0.24.6, after enabling auth.http...
CVE-2026-31946CRITICAL9.8OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From vers...
CVE-2026-30313CRITICAL9.8DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitel...
CVE-2026-30308CRITICAL9.8In its design for automatic terminal command execution, HAI Build Code Generator offers two options: Execute safe comman...
CVE-2026-30306CRITICAL9.8In its design for automatic terminal command execution, SakaDev offers two options: Execute safe commands and execute al...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now