2026 CVE Vulnerabilities

45,294 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-41879HIGH8.2R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password...
CVE-2026-41878HIGH7.1R-SOFT DMS is vulnerable to Insecure Direct Object Reference (IDOR) attack in multiple file download endpoints. The appl...
CVE-2026-41876HIGH8.7R-SOFT DMS is vulnerable to OS Command Injection in konwertujAction() function. The document converter executes shell co...
CVE-2026-40454HIGH7.5Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. Out-of-bounds reads in IoTDB C++...
CVE-2026-40452HIGH7.5Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLas...
CVE-2026-40007HIGH7.5Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB. When pipe_air_gap_receiver_enab...
CVE-2026-40006HIGH7.5Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authenticatio...
CVE-2026-13347HIGH7.5The Hide My WP Lite plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 1.3 via th...
CVE-2026-12685HIGH7.5The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoor that let...
CVE-2026-21055HIGH8.5Improper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute a...
CVE-2026-21049HIGH8.4Out-of-bounds write in libpadm.so library prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary co...
CVE-2026-21048HIGH8.3Out-of-bounds write in parsing DNG format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote ...
CVE-2026-21046HIGH8.4Time-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privil...
CVE-2026-21045HIGH8.3Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote...
CVE-2026-21042HIGH8.4Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code.
CVE-2026-15330HIGH7.3A vulnerability was determined in zhayujie CowAgent up to 2.1.1. Impacted is the function _build_image_content/_download...
CVE-2026-15298HIGH7.2The TelSender plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting in all versions up to, and including,...
CVE-2026-15293HIGH8The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass in all versions up to, and ...
CVE-2026-15291HIGH7.5The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure in all ...
CVE-2026-15290HIGH7.5The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2026-15288HIGH7.5The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation...
CVE-2026-54423HIGH8.2In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface c...
CVE-2026-15070HIGH8.8The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
CVE-2026-13430HIGH7.2The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and...
CVE-2026-15319HIGH7.3A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. This affects the function IPAllowlist of the ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now