2026 CVE Vulnerabilities

70,360 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-3136CRITICAL9.8An improper authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-1-26 allow...
CVE-2026-26886LOW2.7Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /admin/services/manage_servic...
CVE-2026-26885LOW2.7Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /classes/Master.php?f=delete_...
CVE-2026-26884LOW2.7Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /msms/admin/appointments/view...
CVE-2026-26883LOW2.7Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /msms/classes/Master.php?f=de...
CVE-2026-3465LOW3.1A vulnerability was determined in Tuya App and SDK 24.07.11 on Android. Affected by this vulnerability is an unknown fun...
CVE-2026-2637HIGH7.8iBoysoft NTFS for Mac contains a local privilege escalation vulnerability in its privileged helper daemon ntfshelperd. T...
CVE-2026-28518HIGH7.8OpenViking versions 0.2.1 and prior, fixed in commit 46b3e76, contain a path traversal vulnerability in the .ovpack impo...
CVE-2026-25674LOW3.7An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system sto...
CVE-2026-25673HIGH7.5An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django ...
CVE-2026-24103CRITICAL9.8A buffer overflow vulnerability was discovered in goform/formSetMacFilterCfg in Tenda AC15V1.0 V15.03.05.18_multi.
CVE-2026-22891CRITICAL9.8A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig...
CVE-2026-20777HIGH8.1A heap-based buffer overflow vulnerability exists in the Nicolet WFT parsing functionality of The Biosig Project libbios...
CVE-2026-3344MEDIUM4.9A vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS filesystem integrity check and...
CVE-2026-3343MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript...
CVE-2026-3342HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an authenticated privileged administrator to ex...
CVE-2026-3351MEDIUM4.3Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, ...
CVE-2026-3463HIGH7.8A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::binary_writer:...
CVE-2026-2568HIGH7.2The WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin for WordPress is vulnerable to ...
CVE-2026-22886CRITICAL9.8OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product...
CVE-2026-1876HIGH7.5Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET/IP Et...
CVE-2026-1875HIGH7.5Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-EIP EtherN...
CVE-2026-1874HIGH7.5Always-Incorrect Control Flow Implementation vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENE...
CVE-2026-3455MEDIUM6.1Versions of the package mailparser before 3.9.3 are vulnerable to Cross-site Scripting (XSS) via the textToHtml() functi...
CVE-2026-3449LOW3.3Versions of the package @tootallnate/once before 3.0.1 are vulnerable to Incorrect Control Flow Scoping in promise resol...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now