2026 CVE Vulnerabilities

67,186 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4877MEDIUM4.3A security flaw has been discovered in itsourcecode Payroll Management System up to 1.0. This affects an unknown functio...
CVE-2026-4876MEDIUM6.3A vulnerability was identified in itsourcecode Free Hotel Reservation System 1.0. The impacted element is an unknown fun...
CVE-2026-33413HIGH8.8etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9,...
CVE-2026-33396CRITICAL9.9OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authentica...
CVE-2026-33343MEDIUM6.5etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9,...
CVE-2026-2511HIGH7.5The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `mu...
CVE-2026-2389MEDIUM4.9The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versio...
CVE-2026-2231HIGH7.2The Fluent Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all vers...
CVE-2026-1032MEDIUM4.3The Conditional Menus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2026-4887HIGH7.1A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A re...
CVE-2026-4875MEDIUM4.7A vulnerability was determined in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknown fun...
CVE-2026-1961HIGH8A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket pr...
CVE-2026-4809CRITICAL9.8plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the pac...
CVE-2026-4274MEDIUM5.4Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to restrict team-leve...
CVE-2026-24068HIGH8.8The VSL privileged helper does utilize NSXPC for IPC. The implementation of the "shouldAcceptNewConnection" function, wh...
CVE-2026-23398MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: icmp: fix NULL pointer dereference in icmp_tag_vali...
CVE-2026-23397HIGH7.1In the Linux kernel, the following vulnerability has been resolved: nfnetlink_osf: validate individual option lengths i...
CVE-2026-23396MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix NULL deref in mesh_matches_loca...
CVE-2026-4862HIGH8.8A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This issue affects the functio...
CVE-2026-4263MEDIUM6.9Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other u...
CVE-2026-4262MEDIUM6.9Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other u...
CVE-2026-4861HIGH8.8A weakness has been identified in Wavlink WL-NU516U1 260227. This vulnerability affects the function ftext of the file /...
CVE-2026-4860HIGH7.3A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. This affects the function GenericFastJsonR...
CVE-2026-4874LOW3.1A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating t...
CVE-2026-4850CRITICAL9.8A security flaw has been discovered in code-projects Simple Laundry System 1.0. Affected is an unknown function of the f...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now