2026 CVE Vulnerabilities

68,698 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-26939MEDIUM6.5Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoint Resp...
CVE-2026-26933MEDIUM5.7Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Ser...
CVE-2026-30403HIGH7.5There is an arbitrary file read vulnerability in the test connection function of backend database management in wgcloud ...
CVE-2026-26931MEDIUM5.7Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead...
CVE-2026-1005MEDIUM5.3Integer underflow in wolfSSL packet sniffer <= 5.8.4 allows an attacker to cause a buffer overflow in the AEAD decryptio...
CVE-2026-0819HIGH7.1A stack buffer overflow vulnerability exists in wolfSSL's PKCS7 SignedData encoding functionality. In wc_PKCS7_BuildSign...
CVE-2026-3029HIGH7.5A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF ver...
CVE-2026-32869MEDIUM5.4OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of the "Name of Organization" field w...
CVE-2026-32868MEDIUM5.4OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in the ...
CVE-2026-32867CRITICAL9.8OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number ...
CVE-2026-32866MEDIUM5.4OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in a us...
CVE-2026-32865CRITICAL9.8OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when reque...
CVE-2026-30404HIGH7.5The backend database management connection test feature in wgcloud v3.6.3 has a server-side request forgery (SSRF) vulne...
CVE-2026-4427——Rejected reason: Duplicate of CVE-2026-32286
CVE-2026-4426MEDIUM6.5A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by ...
CVE-2026-4424HIGH7.5A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic du...
CVE-2026-32843MEDIUM5.1Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting...
CVE-2026-30711HIGH8.8Devome GRR v4.5.0 was discovered to contain multiple authenticated SQL injection vulnerabilities in the include/session....
CVE-2026-30402CRITICAL9.8An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection functi...
CVE-2026-2369CRITICAL9.1A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resour...
CVE-2026-27043HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGoods Photography allows Path Traversal.This issue...
CVE-2026-22558HIGH7.7An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with aut...
CVE-2026-22557CRITICAL10A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network App...
CVE-2026-3658HIGH7.5The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL...
CVE-2026-3511HIGH8.6Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allow...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now