2026 CVE Vulnerabilities

70,292 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-2746MEDIUM5.3SEPPmail Secure Email Gateway before version 15.0.1 does not properly communicate PGP signature verification results, le...
CVE-2026-27446CRITICAL9.8Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unau...
CVE-2026-27445MEDIUM5.3SEPPmail Secure Email Gateway before version 15.0.1 does not properly verify that a PGP signature was generated by the e...
CVE-2026-27444HIGH7.5SEPPmail Secure Email Gateway before version 15.0.1 incorrectly interprets email addresses in the email headers, causing...
CVE-2026-27443HIGH7.5SEPPmail Secure Email Gateway before version 15.0.1 does not properly sanitize the headers from S/MIME protected MIME en...
CVE-2026-27442HIGH7.5The GINA web interface in SEPPmail Secure Email Gateway before version 15.0.1 does not properly check attachment filenam...
CVE-2026-27441CRITICAL9.8SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS ...
CVE-2026-1236MEDIUM6.4The Envira Gallery for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'justified_ga...
CVE-2026-29120HIGH7.8The /root/anaconda-ks.cfg installation configuration file in International Datacasting Corporation (IDC) SFX Series(SFX2...
CVE-2026-29119CRITICAL9.8International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insec...
CVE-2026-28778CRITICAL9.8International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/ins...
CVE-2026-28777CRITICAL9.8International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account....
CVE-2026-28776CRITICAL9.8International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for th...
CVE-2026-28775CRITICAL9.8An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Cor...
CVE-2026-28774HIGH8.8An OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting...
CVE-2026-28773HIGH8.8The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series Sup...
CVE-2026-28772MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability in the /IDC_Logging/index.cgi endpoint of International Datacasting...
CVE-2026-28771MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in the /index.cgi endpoint of International Datacasting Corp...
CVE-2026-2732MEDIUM5.4The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capa...
CVE-2026-2363MEDIUM6.5The WP-Members Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'order_by' attribute of the...
CVE-2026-28770HIGH8.8Improper neutralization of special elements in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corp...
CVE-2026-28769MEDIUM6.5A path traversal vulnerability exists in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corporatio...
CVE-2026-2025HIGH7.5The Mail Mint WordPress plugin before 1.19.5 does not have authorization in one of its REST API endpoint, allowing unau...
CVE-2026-3242MEDIUM4.8In Concrete CMS below version 9.4.8, a rogue administrator can add stored XSS via the Switch Language block.  The Concre...
CVE-2026-3241MEDIUM4.8In Concrete CMS below version 9.4.8, a stored cross-site scripting (XSS) vulnerability exists in the "Legacy Form" block...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now