2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-91794HIGH7.8An out-of-bounds write vulnerability exists in the PDF rendering process of Foxit PDF Editor/Reader due to insufficient ...
CVE-2026-91793HIGH7.8When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotation rich-text attribut...
CVE-2026-91792HIGH7.8When processing a specially crafted PDF, Foxit PDF Editor/Reader may perform reentrant zoom and layout operations throug...
CVE-2026-91791HIGH7.8When processing a specially crafted PDF file, Foxit PDF Editor/Reader may encounter a reentrant execution condition invo...
CVE-2026-91790HIGH7.8When rendering the page image, Foxit PDF Editor/Reader fails to perform validation on image objects whose optional conte...
CVE-2026-91789HIGH7.8Foxit PDF Editor/Reader’s U3D/GIF texture decoding path contained insufficient validation of image dimensions and relate...
CVE-2026-93508HIGH8.1The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX acti...
CVE-2026-86608HIGH8.2The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor ...
CVE-2026-19438HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Mint Workbench I. T...
CVE-2026-14321HIGH8.2The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it uses for rate limit...
CVE-2026-91777HIGH7.5Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of th...
CVE-2026-91776HIGH7.5TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, a...
CVE-2026-89425HIGH7.5UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error me...
CVE-2026-95927HIGH7.3A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function...
CVE-2026-95926HIGH7.3A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unkno...
CVE-2026-96272HIGH7.5ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search endpoint where the quer...
CVE-2026-96271HIGH7.1Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows au...
CVE-2026-95925HIGH7.3A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown fu...
CVE-2026-95924HIGH7.3A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function ...
CVE-2026-94367HIGH7.2OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup...
CVE-2026-61685HIGH7.5ReactPress is a publishing system for React developers. Prior to version 3.7.0, ReactPress API list endpoints build Type...
CVE-2026-18176HIGH7.4IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive informati...
CVE-2026-18172HIGH7.4IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive informati...
CVE-2026-95819HIGH7.3A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Af...
CVE-2026-18154HIGH8IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive informati...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now