2026 CVE Vulnerabilities

45,376 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-51926HIGH7.5An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php...
CVE-2026-51925HIGH8.1A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to exec...
CVE-2026-51924HIGH8.1An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary code via the file upload and rep...
CVE-2026-51923HIGH8.1An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attac...
CVE-2026-33801HIGH7.1An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Ne...
CVE-2026-33800HIGH7.1An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS o...
CVE-2026-33794HIGH8.2An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand)...
CVE-2026-15270HIGH7.5A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functi...
CVE-2026-0278HIGH7.8Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow...
CVE-2026-0276HIGH7.8A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to...
CVE-2026-59148HIGH8.8Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/...
CVE-2026-54005HIGH7.1Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites where a role has the pages.acce...
CVE-2026-54002HIGH8.5Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins that use the writer...
CVE-2026-49276HIGH7.4Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the writer field in any b...
CVE-2026-13492HIGH8.8The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.65. This...
CVE-2026-0287HIGH7.5Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with...
CVE-2026-0286HIGH7.2A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticate...
CVE-2026-0283HIGH7.2An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software a...
CVE-2026-0281HIGH7.1An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with ...
CVE-2026-0280HIGH7.2An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticat...
CVE-2026-61343HIGH8.6LibreBooking's email template editor save action passes the submitted template name directly into the destination file p...
CVE-2026-59827HIGH8.8Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1...
CVE-2026-59734HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-59721HIGH7.2Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in ad...
CVE-2026-59720HIGH7.5Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now