2026 CVE Vulnerabilities

67,228 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4639HIGH8.8Vitals ESP developed by Galaxy Software Services has a Incorrect Authorization vulnerability, allowing authenticated rem...
CVE-2026-4632HIGH7.3A weakness has been identified in itsourcecode Online Enrollment System 1.0. This vulnerability affects unknown code of ...
CVE-2026-4627HIGH8.6A vulnerability was found in D-Link DIR-825 and DIR-825R 1.0.5/4.5.1. Affected is the function handler_update_system_tim...
CVE-2026-4283CRITICAL9.1The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, ...
CVE-2026-3260——Rejected reason: The Undertow web server enforces a default maximum HTTP request entity size limit. Any request (includi...
CVE-2026-3138MEDIUM6.5The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to unauthorized data loss due to a missing ...
CVE-2026-4744CRITICAL9.3Out-of-bounds Read vulnerability in rizonesoft Notepad3 (‎scintilla/oniguruma/src modules). This vulnerability is associ...
CVE-2026-4743MEDIUM5.2NULL Pointer Dereference vulnerability in taurusxin ncmdump (‎src/utils‎ modules). This vulnerability is associated with...
CVE-2026-4742LOW2.9Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in visualfc liteide (lite...
CVE-2026-4741HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TeamJCD JoyConDroid (app...
CVE-2026-4739CRITICAL9.4Integer Overflow or Wraparound vulnerability in InsightSoftwareConsortium ITK (‎Modules/ThirdParty/Expat/src/expat modul...
CVE-2026-4738CRITICAL9.4Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in OSGeo gdal (frmts/zlib/contrib/...
CVE-2026-4737HIGH7.3Use After Free vulnerability in No-Chicken Echo-Mate (‎SDK/rv1106-sdk/sysdrv/source/kernel/mm modules). This vulnerabili...
CVE-2026-4736HIGH7.3Improper Handling of Values vulnerability in No-Chicken Echo-Mate (SDK/rv1106-sdk/sysdrv/source/kernel/include/net/netfi...
CVE-2026-4735HIGH8.7Deserialization of Untrusted Data vulnerability in DTStack chunjun (‎chunjun-core/src/main/java/com/dtstack/chunjun/util...
CVE-2026-4734CRITICAL9.4Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in yoyofr modizer (libs/libopenmpt...
CVE-2026-4733MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue affect...
CVE-2026-4732HIGH8.4Out-of-bounds Read vulnerability in tildearrow furnace (‎extern/libsndfile-modified/src modules). This vulnerability is ...
CVE-2026-4731HIGH8.5Integer Overflow or Wraparound vulnerability in artraweditor ART (‎rtengine‎ modules). This vulnerability is associated ...
CVE-2026-4626MEDIUM5.4A vulnerability has been found in projectworlds Lawyer Management System 1.0. This impacts an unknown function of the fi...
CVE-2026-4625HIGH7.3A flaw has been found in SourceCodester Online Admission System 1.0. This affects an unknown function of the file /progr...
CVE-2026-4624HIGH7.3A vulnerability was detected in SourceCodester Online Library Management System 1.0. The impacted element is an unknown ...
CVE-2026-4623HIGH7.3A security vulnerability has been detected in DefaultFuction Jeson-Customer-Relationship-Management-System up to 1b4679c...
CVE-2026-33308MEDIUM5.9Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Prior to version 0.13.0, code for client certificate verifi...
CVE-2026-3079MEDIUM6.5The LearnDash LMS plugin for WordPress is vulnerable to blind time-based SQL Injection via the 'filters[orderby_order]' ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now