2026 CVE Vulnerabilities

70,500 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-1565HIGH8.8The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP...
CVE-2026-1241HIGH8.7The Pelco, Inc. Sarix Professional 3 Series Cameras are vulnerable to an authentication bypass issue in their web manage...
CVE-2026-26938HIGH7.7Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which cou...
CVE-2026-26937HIGH7.5Uncontrolled Resource Consumption (CWE-400) in the Timelion component in Kibana can lead Denial of Service via Input Dat...
CVE-2026-22722MEDIUM6.1A malicious actor with authenticated user privileges on a Windows based Workstation host may be able to cause a null poi...
CVE-2026-22715MEDIUM5.9VMWare Workstation and Fusion contain a logic flaw in the management of network packets.  Known attack vectors: A malic...
CVE-2026-26936HIGH7.5Inefficient Regular Expression Complexity (CWE-1333) in the AI Inference Anonymization Engine in Kibana can lead Denial ...
CVE-2026-26935HIGH7.5Improper Input Validation (CWE-20) in the internal Content Connectors search endpoint in Kibana can lead Denial of Servi...
CVE-2026-26934MEDIUM6.5Improper Validation of Specified Quantity in Input (CWE-1284) in Kibana can allow an authenticated attacker with view-on...
CVE-2026-26932HIGH7.5Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service ...
CVE-2026-26682HIGH7.8An issue in fastCMS before v.0.1.6 allows a local attacker to execute arbitrary code via the PluginController.java compo...
CVE-2026-26227MEDIUM6.3VideoLAN VLC for Android prior to version 3.7.0 contains an authentication bypass in the Remote Access Server feature du...
CVE-2026-23750HIGH8.1Golioth Pouch version 0.1.0, prior to commit 1b2219a1, contains a heap-based buffer overflow in BLE GATT server certific...
CVE-2026-23749LOW2.9Golioth Firmware SDK version 0.19.1 prior to 0.22.0, fixed in commit 0e788217, contain an out-of-bounds read due to impr...
CVE-2026-23748MEDIUM6.3Golioth Firmware SDK version 0.10.0 prior to 0.22.0, fixed in commit d7f55b38, contain an out-of-bounds read in LightDB ...
CVE-2026-23747MEDIUM6.3Golioth Firmware SDK version 0.10.0 prior to 0.22.0, fixed in commit 48f521b, contain a stack-based buffer overflow in P...
CVE-2026-28296MEDIUM4.3A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplyi...
CVE-2026-28295MEDIUM4.3A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrar...
CVE-2026-26265HIGH7.5Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an IDOR vulnerabil...
CVE-2026-26228MEDIUM4.9VideoLAN VLC for Android prior to version 3.7.0 contains a path traversal vulnerability in the Remote Access Server rout...
CVE-2026-26207MEDIUM5.4Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, `discourse-policy`...
CVE-2026-26078HIGH7.5Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, when the `patreon_...
CVE-2026-3071HIGH8.4Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to ar...
CVE-2026-2244HIGH8.4A vulnerability in Google Cloud Vertex AI Workbench from 7/21/2025 to 01/30/2026 allows an attacker to exfiltrate valid ...
CVE-2026-26077MEDIUM6.5Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, several webhook en...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now