2026 CVE Vulnerabilities

67,491 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-28198HIGH8.8An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptograp...
CVE-2026-28197HIGH8.8An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially cr...
CVE-2026-21806LOW3.1HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows...
CVE-2026-93578MEDIUM5.9A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSP...
CVE-2026-93575HIGH7.5A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a ...
CVE-2026-93572HIGH7.5A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sendin...
CVE-2026-93563HIGH7.5A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-midd...
CVE-2026-93561MEDIUM6.5A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and ...
CVE-2026-81627HIGH8.2A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias rem...
CVE-2026-92976MEDIUM5.1A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T-Systems’ TAO 2.0 suite. A...
CVE-2026-90884MEDIUM5.4The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' parameter in all v...
CVE-2026-87915HIGH7.2The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress ...
CVE-2026-87743HIGH7.5A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normal...
CVE-2026-18405HIGH7.2The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vul...
CVE-2026-15797MEDIUM6.4The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress ...
CVE-2026-15579HIGH8.8An out-of-bounds write vulnerability exists in some of the Ethernet switches because of improper validation of the usern...
CVE-2026-85410HIGH8.1The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template...
CVE-2026-83561HIGH7.2The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comm...
CVE-2026-6205HIGH8.1An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-...
CVE-2026-56597LOW3.1HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthe...
CVE-2026-56595LOW3.1HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin he...
CVE-2026-56592MEDIUM6.5HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate a...
CVE-2026-56590MEDIUM6.4HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation c...
CVE-2026-4036MEDIUM6.5An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Sharing API in ...
CVE-2026-40539HIGH7.1An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-1...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now