2026 CVE Vulnerabilities

69,033 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-2257MEDIUM6.4The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including...
CVE-2026-29776LOW3.1FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, Integer Underflow in update_read_cache...
CVE-2026-29775HIGH8.2FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap out-of-bounds read/...
CVE-2026-29774HIGH8.2FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap buffer overflow occ...
CVE-2026-29079HIGH7.5Lexbor is a web browser engine library. Prior to 2.7.0, a type‑confusion vulnerability exists in Lexbor’s HTML fragment ...
CVE-2026-29078HIGH7.5Lexbor is a web browser engine library. Prior to 2.7.0, the ISO‑2022‑JP encoder in Lexbor fails to reset the temporary s...
CVE-2026-26954CRITICAL10SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, whic...
CVE-2026-25823CRITICAL9.8HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23...
CVE-2026-25819HIGH7.5HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23...
CVE-2026-25818CRITICAL9.1HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23...
CVE-2026-25817HIGH8.8HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23...
CVE-2026-25076HIGH8.5Anchore Enterprise versions before 5.25.1 contain an SQL injection vulnerability in the GraphQL Reports API. An authenti...
CVE-2026-24097MEDIUM4.3Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows...
CVE-2026-23943MEDIUM5.3Improper Handling of Highly Compressed Data (Compression Bomb) vulnerability in Erlang OTP ssh (ssh_transport modules) a...
CVE-2026-23942MEDIUM5.4Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (ssh_sftpd mo...
CVE-2026-23941CRITICAL9.4Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module)...
CVE-2026-23940MEDIUM6.5Uncontrolled Resource Consumption vulnerability in hexpm hexpm/hexpm allows Excessive Allocation. Publishing an oversiz...
CVE-2026-22216MEDIUM5.3wpDiscuz before 7.6.47 contains a missing rate limiting vulnerability that allows unauthenticated attackers to subscribe...
CVE-2026-22215MEDIUM5.4wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability in the getFollowsPage() function that allows ...
CVE-2026-22210MEDIUM6.1wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability that allows attackers to inject malicious code thro...
CVE-2026-22209MEDIUM5.5wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability in the customCss field that allows administrators t...
CVE-2026-22204MEDIUM5.3wpDiscuz before 7.6.47 contains an email header injection vulnerability that allows attackers to manipulate mail recipie...
CVE-2026-22203MEDIUM6.9wpDiscuz before 7.6.47 contains an information disclosure vulnerability that allows administrators to inadvertently expo...
CVE-2026-22202MEDIUM6.5wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments ...
CVE-2026-22201MEDIUM6.9wpDiscuz before 7.6.47 contains an IP spoofing vulnerability in the getIP() function that allows attackers to bypass IP-...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now