2026 CVE Vulnerabilities

48,366 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-19014MEDIUM4.3Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumpti...
CVE-2026-19012MEDIUM5.3Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service...
CVE-2026-15972HIGH7.5Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of servi...
CVE-2026-15970MEDIUM4.2Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypa...
CVE-2026-71852MEDIUM4.8pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and larg...
CVE-2026-71851CRITICAL9crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in Crypt...
CVE-2026-71850MEDIUM4.8Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to 4.12.33, memo() from...
CVE-2026-71849LOW3.7Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy H...
CVE-2026-71848MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.0 to 4.12.33, the langua...
CVE-2026-71847HIGH8.7Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consume...
CVE-2026-70561HIGH7.1TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user,...
CVE-2026-69127MEDIUM6.9Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handl...
CVE-2026-66000LOW2.3Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation...
CVE-2026-48098HIGH7.3NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Vers...
CVE-2026-48097HIGH7.8NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Vers...
CVE-2026-19231HIGH7.3A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects ...
CVE-2026-19230LOW3.5A vulnerability was identified in SourceCodester Photo Share Website 1.0. This affects an unknown part of the file /soci...
CVE-2026-17435LOW2.5File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files. When th...
CVE-2026-11430HIGH7.3Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. When the webhook featu...
CVE-2026-66058MEDIUM5.3Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follo...
CVE-2026-64638HIGH8.9WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici...
CVE-2026-64637CRITICAL9.9Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an ...
CVE-2026-64636HIGH7.7An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to rea...
CVE-2026-56818MEDIUM6.5Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the Redis...
CVE-2026-47364MEDIUM6.5In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datado...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now