2026 CVE Vulnerabilities

70,360 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-1945HIGH7.2The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_ema...
CVE-2026-1651MEDIUM6.5The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the 'workflow_ids' para...
CVE-2026-1273HIGH7.2The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Server-S...
CVE-2026-3266CRITICAL9.8Missing Authorization vulnerability in OpenText™ Filr allows Authentication Bypass. The vulnerability could allow unauth...
CVE-2026-3076——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-2363. Reason: This candidate is a r...
CVE-2026-28289HIGH8.1FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-...
CVE-2026-27981HIGH7.4HomeBox is a home inventory and organization system. Prior to 0.24.0, the authentication rate limiter (authRateLimiter) ...
CVE-2026-27971CRITICAL9.8Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization ...
CVE-2026-27932HIGH7.5joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar...
CVE-2026-27905HIGH7.8BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4....
CVE-2026-27622HIGH7.8OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-27601MEDIUM5.9Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recur...
CVE-2026-27600MEDIUM4.3HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, the notifier functionality allows authenticat...
CVE-2026-26279CRITICAL9.1Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== ins...
CVE-2026-26272MEDIUM5.4HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, a stored cross-site scripting (XSS) vulnerabi...
CVE-2026-26266MEDIUM6.1AliasVault is a privacy-first password manager with built-in email aliasing. A stored cross-site scripting (XSS) vulnera...
CVE-2026-25590MEDIUM6.1The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents...
CVE-2026-3487HIGH7.2A vulnerability was found in itsourcecode College Management System 1.0. This issue affects some unknown processing of t...
CVE-2026-3224CRITICAL9.8Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and ear...
CVE-2026-3204CRITICAL9.8Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers...
CVE-2026-3130CRITICAL9.8Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker...
CVE-2026-2590CRITICAL9.8Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions...
CVE-2026-27012CRITICAL9.8OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a pri...
CVE-2026-25146HIGH8.1OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to b...
CVE-2026-24898CRITICAL9.8OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0,...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now