2026 CVE Vulnerabilities

45,451 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-48957HIGH8.8An improper access check allows unauthorized users to access com_privacy datasets.
CVE-2026-48948HIGH8.8An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
CVE-2026-57851HIGH8.5MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allo...
CVE-2026-23698HIGH8.6Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import featur...
CVE-2026-23697HIGH8.8Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve ...
CVE-2026-14904HIGH7.1AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create an...
CVE-2026-56812HIGH7.5Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript clie...
CVE-2026-56811HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) a...
CVE-2026-6101HIGH7.5The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary File Write in versions up to a...
CVE-2026-53479HIGH7.2Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-44938HIGH8.8A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from na...
CVE-2026-13696HIGH8.8Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in HAVELSAN Inc. Lima...
CVE-2026-11348HIGH8.1Improper verification of cryptographic signature vulnerability in HAVELSAN Inc. Liman MYS allows Fake the Source of Data...
CVE-2026-11340HIGH8.3Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained b...
CVE-2026-14476HIGH8A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitiz...
CVE-2026-14474HIGH8.8A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD ...
CVE-2026-11610HIGH8.8A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SA...
CVE-2026-58384HIGH7.8A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation...
CVE-2026-8377HIGH8.2Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Colle...
CVE-2026-5799HIGH7.5Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime a...
CVE-2026-5730HIGH7.5Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime a...
CVE-2026-57871HIGH7.1Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overw...
CVE-2026-57869HIGH7.1Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstat...
CVE-2026-57868HIGH7.1MicroRealEstate is affected by broken object-level access controls in PDF generator functionality. This issue affects M...
CVE-2026-57867HIGH8.8MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now