2026 CVE Vulnerabilities

70,490 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-27753MEDIUM6.9SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication bypass vulnerability that allows re...
CVE-2026-27752HIGH8.2SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, al...
CVE-2026-27751CRITICAL9.8SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remot...
CVE-2026-26862HIGH8.3CleverTap Web SDK version 1.15.2 and earlier is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessag...
CVE-2026-26861HIGH8.3CleverTap Web SDK version 1.15.2 and earlier is vulnerable to Cross-Site Scripting (XSS) via window.postMessage. The han...
CVE-2026-21619HIGH7.5Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), ...
CVE-2026-2293CRITICAL9.8A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fas...
CVE-2026-25147HIGH7.1OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio...
CVE-2026-24488MEDIUM6.5OpenEMR is a free and open source electronic health records and medical practice management application. In versions up ...
CVE-2026-3304HIGH7.5Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allo...
CVE-2026-3277MEDIUM6.5The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client s...
CVE-2026-2750CRITICAL9.8Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tick...
CVE-2026-2749HIGH8.8Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue aff...
CVE-2026-2359HIGH7.5Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allo...
CVE-2026-3327MEDIUM4.8Authenticated Iframe Injection in Dato CMS Web Previews plugin. This vulnerability permits a malicious authenticated use...
CVE-2026-3223HIGH7.8Arbitrary file write & potential privilege escalation exploiting zip slip vulnerability in Google Web Designer.
CVE-2026-2751CRITICAL9.8Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web ...
CVE-2026-2831MEDIUM4.9The MailArchiver plugin for WordPress is vulnerable to SQL Injection via the ‘logid’ parameter in all versions up to, an...
CVE-2026-24352CRITICAL9.8PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the sa...
CVE-2026-24351MEDIUM5.4PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can injec...
CVE-2026-24350MEDIUM5.4PluXml CMS is vulnerable to Stored XSS in file uploading functionality. An authenticated attacker can upload an SVG file...
CVE-2026-1434MEDIUM6.1Omega-PSIR is vulnerable to Reflected XSS via the lang parameter. An attacker can craft a malicious URL that, when opene...
CVE-2026-21660CRITICAL9.8A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in...
CVE-2026-21659CRITICAL9.8Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in John...
CVE-2026-1305MEDIUM5.3The Japanized for WooCommerce plugin for WordPress is vulnerable to Improper Authentication in versions up to, and inclu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now