2026 CVE Vulnerabilities

67,468 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-93488HIGH7.5A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because...
CVE-2026-28199LOW3.3An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underly...
CVE-2026-28198HIGH8.8An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptograp...
CVE-2026-28197HIGH8.8An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially cr...
CVE-2026-21806LOW3.1HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows...
CVE-2026-93578MEDIUM5.9A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSP...
CVE-2026-93575HIGH7.5A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a ...
CVE-2026-93572HIGH7.5A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sendin...
CVE-2026-93563HIGH7.5A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-midd...
CVE-2026-93561MEDIUM6.5A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and ...
CVE-2026-81627HIGH8.2A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias rem...
CVE-2026-92976MEDIUM5.1A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T-Systems’ TAO 2.0 suite. A...
CVE-2026-90884MEDIUM5.4The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' parameter in all v...
CVE-2026-87915HIGH7.2The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress ...
CVE-2026-87743HIGH7.5A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normal...
CVE-2026-18405HIGH7.2The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vul...
CVE-2026-15797MEDIUM6.4The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress ...
CVE-2026-15579HIGH8.8An out-of-bounds write vulnerability exists in some of the Ethernet switches because of improper validation of the usern...
CVE-2026-85410HIGH8.1The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template...
CVE-2026-83561HIGH7.2The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comm...
CVE-2026-6205HIGH8.1An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-...
CVE-2026-56597LOW3.1HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthe...
CVE-2026-56595LOW3.1HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin he...
CVE-2026-56592MEDIUM6.5HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate a...
CVE-2026-56590MEDIUM6.4HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation c...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now