2026 CVE Vulnerabilities

70,269 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-22397HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-22395HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-22394HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-22392HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-22390CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in Builderall Builderall Builder for WordPress b...
CVE-2026-22389HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-22387HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-22385HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-3523MEDIUM4.9The Apocalypse Meow plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, ...
CVE-2026-3034MEDIUM6.4The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _ob_spacera...
CVE-2026-2899MEDIUM6.5The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and ...
CVE-2026-2365HIGH7.2The Fluent Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fluentform_step_form_sav...
CVE-2026-29127HIGH7.8The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. ...
CVE-2026-26034HIGH8.5UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Incorrect Default Permissions (CWE-276) vul...
CVE-2026-26033HIGH8.4UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Unquoted Search Path or Element (CWE-428) v...
CVE-2026-3381CRITICAL9.8Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib. Compress::Raw::Zlib incl...
CVE-2026-3257CRITICAL9.8UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library. UnQLite for Perl emb...
CVE-2026-29126HIGH7.8Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in International Data Casting (IDC) ...
CVE-2026-29125MEDIUM4.7IDC SFX2100 Satalite Recievers set the `/etc/resolv.conf` file to be world-writable by any local user, allowing DNS reso...
CVE-2026-29124HIGH7.8Multiple SUID root-owned binaries are found in /home/monitor/terminal, /home/monitor/kore-terminal, /home/monitor/IDE-DP...
CVE-2026-29123HIGH7.8A SUID root-owned binary in /home/xd/terminal/XDTerminal in International Data Casting (IDC) SFX2100 on Linux allows a l...
CVE-2026-29122MEDIUM5.5International Data Casting (IDC) SFX2100 satellite receiver comes with the `/bin/date` utility installed with the setuid...
CVE-2026-29121HIGH7.8International Data Casting (IDC) SFX2100 satellite receiver comes with the `/sbin/ip` utility installed with the setuid ...
CVE-2026-2836HIGH8.1A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction. The...
CVE-2026-2835CRITICAL9.1An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now