2026 CVE Vulnerabilities

67,685 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40532MEDIUM6.5A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-...
CVE-2026-40531MEDIUM4.3An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-690...
CVE-2026-40530HIGH8An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manage...
CVE-2026-21848MEDIUM5HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticat...
CVE-2026-21822MEDIUM6.3HCLSoftware AppScan 360° was affected by a Path Traversal vulnerability in the ASReportService component. Improper handl...
CVE-2026-13684CRITICAL9.8An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-6905...
CVE-2026-13683LOW2.7An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in EventScheduler ...
CVE-2026-13673HIGH8.8An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM)...
CVE-2026-13666LOW3.5An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Man...
CVE-2026-13639CRITICAL9.8An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-...
CVE-2026-13635MEDIUM5.3An improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation Manager (DSM) before 7.2.1-...
CVE-2026-13623MEDIUM4.8An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in Sy...
CVE-2026-93494HIGH7.5A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending ...
CVE-2026-93493MEDIUM5.9A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by prov...
CVE-2026-92622MEDIUM6.4The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lightbox_class' Shortcode...
CVE-2026-92554MEDIUM6.1The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Reflecte...
CVE-2026-92249MEDIUM6.1The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter i...
CVE-2026-90981MEDIUM6.1The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting...
CVE-2026-89059HIGH7.5A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing ...
CVE-2026-89058HIGH7.4A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Ori...
CVE-2026-85705HIGH7.5The Location Manager plugin for WordPress is vulnerable to generic SQL Injection via 'latitude' and 'longitude' REST API...
CVE-2026-85652MEDIUM6.5The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injectio...
CVE-2026-75961MEDIUM4.9The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the ...
CVE-2026-75157HIGH7.5Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `E...
CVE-2026-67103HIGH7.6HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now