2026 CVE Vulnerabilities

67,418 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-0819HIGH7.1A stack buffer overflow vulnerability exists in wolfSSL's PKCS7 SignedData encoding functionality. In wc_PKCS7_BuildSign...
CVE-2026-3029HIGH7.5A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF ver...
CVE-2026-32869MEDIUM5.4OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of the "Name of Organization" field w...
CVE-2026-32868MEDIUM5.4OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in the ...
CVE-2026-32867CRITICAL9.8OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number ...
CVE-2026-32866MEDIUM5.4OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in a us...
CVE-2026-32865CRITICAL9.8OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when reque...
CVE-2026-30404HIGH7.5The backend database management connection test feature in wgcloud v3.6.3 has a server-side request forgery (SSRF) vulne...
CVE-2026-4427——Rejected reason: Duplicate of CVE-2026-32286
CVE-2026-4426MEDIUM6.5A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by ...
CVE-2026-4424HIGH7.5A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic du...
CVE-2026-32843MEDIUM5.1Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting...
CVE-2026-30711HIGH8.8Devome GRR v4.5.0 was discovered to contain multiple authenticated SQL injection vulnerabilities in the include/session....
CVE-2026-30402CRITICAL9.8An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection functi...
CVE-2026-2369CRITICAL9.1A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resour...
CVE-2026-27043HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGoods Photography allows Path Traversal.This issue...
CVE-2026-22558HIGH7.7An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with aut...
CVE-2026-22557CRITICAL10A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network App...
CVE-2026-3658HIGH7.5The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL...
CVE-2026-3511HIGH8.6Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allow...
CVE-2026-27070HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPEverest Everest ...
CVE-2026-27068HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Howard Websit...
CVE-2026-27067CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor mobile-app-editor allows Uploa...
CVE-2026-27065CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-25445HIGH8.8Deserialization of Untrusted Data vulnerability in Membership Software WishList Member X allows Object Injection.This is...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now