2026 CVE Vulnerabilities

70,015 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-30790——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-30789CRITICAL9.8Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts v...
CVE-2026-30785MEDIUM5.5Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Ins...
CVE-2026-30784——Rejected reason: This CVE ID has been withdrawn by its CVE Numbering Authority.
CVE-2026-30783CRITICAL9.8A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Cl...
CVE-2026-26377MEDIUM5.4Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via the N...
CVE-2026-25048HIGH7.5xgrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to version 0.1.32,...
CVE-2026-3598HIGH7.5Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-server-pro RustDesk Server Pro rustdesk-serve...
CVE-2026-30791HIGH7.5Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-client RustDesk Client rustdesk-client on Win...
CVE-2026-27750HIGH7Avira Internet Security contains a time-of-check time-of-use (TOCTOU) vulnerability in the Optimizer component. A privil...
CVE-2026-27749HIGH7.8Avira Internet Security contains a deserialization of untrusted data vulnerability in the System Speedup component. The ...
CVE-2026-27748HIGH7.1Avira Internet Security contains an improper link resolution vulnerability in the Software Updater component. During the...
CVE-2026-1720HIGH8.8The WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation plugin for WordPress is vulne...
CVE-2026-2599CRITICAL9.8The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in ...
CVE-2026-3236MEDIUM4.3In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting i...
CVE-2026-21628CRITICAL9.8A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading t...
CVE-2026-1605HIGH7.5In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed...
CVE-2026-28551MEDIUM4.7Race condition vulnerability in the device security management module. Impact: Successful exploitation of this vulnerabi...
CVE-2026-28549MEDIUM4.7Race condition vulnerability in the permission management service. Impact: Successful exploitation of this vulnerability...
CVE-2026-28548MEDIUM5.5Vulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability m...
CVE-2026-28547MEDIUM5.5Vulnerability of uninitialized pointer access in the scanning module. Impact: Successful exploitation of this vulnerabil...
CVE-2026-28546MEDIUM5.5Buffer overflow vulnerability in the scanning module. Impact: Successful exploitation of this vulnerability may affect a...
CVE-2026-28542MEDIUM5.5Permission bypass vulnerability in the system service framework. Impact: Successful exploitation of this vulnerability m...
CVE-2026-2893MEDIUM6.5The Page and Post Clone plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' parameter in the content_...
CVE-2026-28552HIGH7.5Out-of-bounds write vulnerability in the IMS module. Impact: Successful exploitation of this vulnerability may affect av...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now