2026 CVE Vulnerabilities

70,492 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-21659CRITICAL9.8Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in John...
CVE-2026-1305MEDIUM5.3The Japanized for WooCommerce plugin for WordPress is vulnerable to Improper Authentication in versions up to, and inclu...
CVE-2026-2383MEDIUM6.4The Simple Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field in all ve...
CVE-2026-2362MEDIUM6.4The WP Accessibility plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'alt' attribute...
CVE-2026-2252HIGH7.5An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via craft...
CVE-2026-2251CRITICAL9.8Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows...
CVE-2026-21658CRITICAL9.8Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Joh...
CVE-2026-21657CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD al...
CVE-2026-21656CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD al...
CVE-2026-21654CRITICAL9.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Cont...
CVE-2026-1627HIGH8.1An attacker may exploit the use of outdated and weak MAC algorithms in the device’s SSH service to potentially compromis...
CVE-2026-1626CRITICAL9.1An attacker may exploit the use of weak CBC-based cipher suites in the device’s SSH service to potentially observe or ma...
CVE-2026-27776HIGH8.8IM-LogicDesigner module of intra-mart Accel Platform contains insecure deserialization issue. This can be exploited only...
CVE-2026-0980HIGH8.8A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An...
CVE-2026-0871MEDIUM4.9A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can vi...
CVE-2026-3302MEDIUM6.1A weakness has been identified in SourceCodester Doctor Appointment System 1.0. Affected by this issue is some unknown f...
CVE-2026-3301CRITICAL9.8A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the functi...
CVE-2026-3293MEDIUM5.5A weakness has been identified in snowflakedb snowflake-jdbc up to 4.0.1. Impacted is the function SdkProxyRoutePlanner ...
CVE-2026-28372HIGH7.8telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service creden...
CVE-2026-27653MEDIUM6.7The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permission...
CVE-2026-3292HIGH8.8A security vulnerability has been detected in jizhiCMS up to 2.5.6. Affected is the function findAll in the library frph...
CVE-2026-3289CRITICAL9.8A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file Templ...
CVE-2026-3287CRITICAL9.8A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the...
CVE-2026-28370CRITICAL9.1In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage...
CVE-2026-1558MEDIUM5.3The WP Recipe Maker plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) in versions up to, ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now