2026 CVE Vulnerabilities

68,769 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32587MEDIUM5.4Missing Authorization vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Exploiting Incorrectly Configured Access...
CVE-2026-32583MEDIUM5.3Missing Authorization vulnerability in Webnus Inc. Modern Events Calendar allows Exploiting Incorrectly Configured Acces...
CVE-2026-4243LOW2.5A weakness has been identified in La Nacion App 10.2.25 on Android. This impacts an unknown function of the file source/...
CVE-2026-4242LOW2.5A security flaw has been discovered in BabyChakra Pregnancy & Parenting App up to 5.4.3.0 on Android. This affects an un...
CVE-2026-2455MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to canonicalize IPv4-mapped IPv6 addres...
CVE-2026-25369HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexmls Flexmls® I...
CVE-2026-24692MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly enforce read permissions in...
CVE-2026-22545LOW3.5Mattermost versions 10.11.x <= 10.11.10 fail to validate user's authentication method when processing account auth type ...
CVE-2026-21386MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent error responses when ...
CVE-2026-4265MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to validate team-specific upload_file p...
CVE-2026-4255HIGH7.8A DLL search order hijacking vulnerability in Thermalright TR-VISION HOME on Windows (64-bit) allows a local attacker to...
CVE-2026-4241MEDIUM6.3A vulnerability was identified in itsourcecode College Management System 1.0. The impacted element is an unknown functio...
CVE-2026-4240HIGH7.5A vulnerability was determined in Open5GS up to 2.7.6. The affected element is the function smf_gx_cca_cb/smf_gy_cca_cb/...
CVE-2026-4239LOW3.5A vulnerability was found in Lagom WHMCS Template up to 2.3.7. Impacted is an unknown function of the component Datatabl...
CVE-2026-4238MEDIUM4.7A vulnerability has been found in itsourcecode College Management System 1.0. This issue affects some unknown processing...
CVE-2026-4237HIGH7.3A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the ...
CVE-2026-4236HIGH7.3A security vulnerability has been detected in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function...
CVE-2026-4235HIGH7.3A weakness has been identified in itsourcecode Online Enrollment System 1.0. This issue affects some unknown processing ...
CVE-2026-4234MEDIUM6.3A security flaw has been discovered in SSCMS 7.4.0. This vulnerability affects unknown code of the file SitesAddControll...
CVE-2026-4233MEDIUM4.3A vulnerability was identified in ThingsGateway 12. This affects an unknown part of the file /api/file/download. The man...
CVE-2026-4232HIGH7.3A vulnerability was determined in Tiandy Integrated Management Platform 7.17.0. Affected by this issue is some unknown f...
CVE-2026-4231HIGH7.3A vulnerability was found in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is the function update_sql/run_s...
CVE-2026-4230MEDIUM6.3A vulnerability has been found in vanna-ai vanna up to 2.0.2. Affected is the function update_sql of the file src/vanna/...
CVE-2026-4229HIGH7.3A flaw has been found in vanna-ai vanna up to 2.0.2. This impacts the function remove_training_data of the file src/vann...
CVE-2026-4228CRITICAL9.8A vulnerability was detected in LB-LINK BL-WR9000 2.4.9. This affects the function sub_458754 of the file /goform/set_wi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now