2026 CVE Vulnerabilities

68,737 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-1217MEDIUM5.4The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2026-22730HIGH8.8A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metada...
CVE-2026-22729HIGH8.6A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass...
CVE-2026-22323HIGH7.1A CSRF vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to trick ...
CVE-2026-22322HIGH7.1A stored cross‑site scripting (XSS) vulnerability in the Link Aggregation configuration interface allows an unauthentica...
CVE-2026-22321MEDIUM5.3A stack-based buffer overflow in the device's Telnet/SSH CLI login routine occurs when a unauthenticated attacker send a...
CVE-2026-22320MEDIUM6.5A stack-based buffer overflow in the CLI's TFTP file‑transfer command handling allows a low-privileged attacker with Tel...
CVE-2026-22319MEDIUM4.9A stack-based buffer overflow in the device's file installation workflow allows a high-privileged attacker to send overs...
CVE-2026-22318MEDIUM4.9A stack-based buffer overflow vulnerability in the device's file transfer parameter workflow allows a high-privileged at...
CVE-2026-22317HIGH7.2A command injection vulnerability in the device’s Root CA certificate transfer workflow allows a high-privileged attacke...
CVE-2026-22316MEDIUM6.5A remote attacker with user privileges for the webUI can use the setting of the TFTP Filename with a POST Request to tri...
CVE-2026-3512MEDIUM6.1The Writeprint Stylometry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'p' GET parameter...
CVE-2026-32608HIGH7Glances is an open-source system cross-platform monitoring tool. The Glances action system allows administrators to conf...
CVE-2026-32606HIGH7.6IncusOS is an immutable OS image dedicated to running Incus. Prior to 202603142010, the default configuration of systemd...
CVE-2026-32596HIGH7.5Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.2, Glances web server runs without authent...
CVE-2026-32268HIGH8.7The Azure Blob Storage for Craft CMS plugin provides an Azure Blob Storage integration for Craft CMS. In versions on the...
CVE-2026-4366MEDIUM5.8A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirect...
CVE-2026-33189——Rejected reason: Further research determined the issue originates from a different product.
CVE-2026-33188——Rejected reason: Further research determined the issue originates from a different product.
CVE-2026-33187——Rejected reason: Further research determined the issue originates from a different product.
CVE-2026-33058MEDIUM6.5Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQ...
CVE-2026-32266LOW2.4The Google Cloud Storage for Craft CMS plugin provides a Google Cloud Storage integration for Craft CMS. In versions on ...
CVE-2026-32265MEDIUM6.9The Amazon S3 for Craft CMS plugin provides an Amazon S3 integration for Craft CMS. In versions 2.0.2 through 2.2.4, una...
CVE-2026-32256HIGH7.5music-metadata is a metadata parser for audio and video media files. Prior to version 11.12.3, music-metadata's ASF pars...
CVE-2026-32254HIGH7.1Kube-router is a turnkey solution for Kubernetes networking. Prior to version 2.8.0, Kube-router's proxy module does not...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now