2026 CVE Vulnerabilities

45,449 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-57895HIGH8.5Incorrect default permissions issue exists in Pupsman versions prior to 3.9.0. An attacker can place a malicious executa...
CVE-2026-56437HIGH8.4Uncontrolled search path element issue exists in Pupsman versions prior to 3.9.0. If a crafted DLL file is placed in the...
CVE-2026-14495HIGH8.8The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all vers...
CVE-2026-14489HIGH8.8The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the...
CVE-2026-9842HIGH7.5The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,...
CVE-2026-14482HIGH8.8The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. The v...
CVE-2026-14244HIGH7.5The Jssor Slider by jssor.com plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu...
CVE-2026-14158HIGH8.8The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including...
CVE-2026-60000HIGH7.5sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive au...
CVE-2026-59999HIGH7.5In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not...
CVE-2026-55436HIGH7.4Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and pr...
CVE-2026-55429HIGH8.7Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55428HIGH8.2Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55427HIGH8.3Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-59704HIGH7.1Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metada...
CVE-2026-55077HIGH7.2Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55076HIGH7.4Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-51937HIGH7.5An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsAp...
CVE-2026-14895HIGH7.5String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. The trim and rtri...
CVE-2026-14380HIGH8.8DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is ass...
CVE-2026-55418HIGH8.6FastGPT is an open source AI knowledge base platform. Prior to v4.15.0-beta5, two FastGPT file handlers authorize an unr...
CVE-2026-55408HIGH8.4Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Reader is vulnerable to remote code execution throu...
CVE-2026-55075HIGH7.4Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-54607HIGH7.7FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta4, the HTTP-tool OpenAPI schema importer valid...
CVE-2026-54602HIGH7.1FastGPT is a knowledge-based AI application platform. Prior to 4.15.0, GET /api/core/ai/record/getRecord authenticates t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now