2026 CVE Vulnerabilities

69,033 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-22199HIGH8.7Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi en...
CVE-2026-22193HIGH7.5wpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions() function where string parame...
CVE-2026-22192CRITICAL9.9Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated att...
CVE-2026-22191MEDIUM5.2Beghelli Sicuro24 SicuroWeb contains a template injection vulnerability that allows attackers to inject arbitrary Angula...
CVE-2026-22183MEDIUM5.4wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability in the inline comment preview functionality ...
CVE-2026-22182HIGH8.7wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigge...
CVE-2026-1704MEDIUM4.3The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Ins...
CVE-2026-1668CRITICAL9.8The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out...
CVE-2026-0957HIGH8.5There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted file in Digilent DASYL...
CVE-2026-0956HIGH8.5There is a memory corruption vulnerability due to an out-of-bounds read when loading a corrupted file in Digilent DASYLa...
CVE-2026-0955HIGH8.5There is a memory corruption vulnerability due to an out-of-bounds read when loading a corrupted file in Digilent DASYLa...
CVE-2026-0954HIGH8.5There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted DSB file in Digilent D...
CVE-2026-0835MEDIUM5.4IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 ...
CVE-2026-3611CRITICAL10The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-...
CVE-2026-2581MEDIUM5.9This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). In vulne...
CVE-2026-2229HIGH7.5ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_m...
CVE-2026-1528HIGH7.5ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's Byt...
CVE-2026-1527MEDIUM4.6ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject...
CVE-2026-1526HIGH7.5The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessa...
CVE-2026-32274HIGH7.5Black is the uncompromising Python code formatter. Starting in version 24.3.0 and prior to version 26.3.1, Black writes ...
CVE-2026-32269MEDIUM6.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32260CRITICAL9.8Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.7.0 to 2.7.1, A command injection vulnerability exist...
CVE-2026-32259MEDIUM6.7ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9...
CVE-2026-32251MEDIUM6.5Tolgee is an open-source localization platform. Prior to 3.166.3, the XML parsers used for importing Android XML resourc...
CVE-2026-32249MEDIUM5.5Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encoun...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now