2026 CVE Vulnerabilities

42,999 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-71407MEDIUM5.6A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an...
CVE-2026-70468HIGH8.1A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7....
CVE-2026-70467LOW3.8A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM...
CVE-2026-70466MEDIUM5.3A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7....
CVE-2026-57858HIGH8.9Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagMa...
CVE-2026-53996HIGH7NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unpr...
CVE-2026-47226MEDIUM6.5Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload...
CVE-2026-26035CRITICAL9.8An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6....
CVE-2026-70560MEDIUM5.4Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-pri...
CVE-2026-70465HIGH8.1A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7....
CVE-2026-18044LOW3.7The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later use...
CVE-2026-17008MEDIUM5.3The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status i...
CVE-2026-16990MEDIUM5.3The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-si...
CVE-2026-16747MEDIUM6.5The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes...
CVE-2026-16621MEDIUM5.3The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succee...
CVE-2026-15213MEDIUM5.3The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-...
CVE-2026-15045MEDIUM6.5The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against...
CVE-2026-11325HIGH8.8Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, ...
CVE-2026-68868The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when re...
CVE-2026-67284MEDIUM5.3Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authentica...
CVE-2026-64955MEDIUM6.1When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CS...
CVE-2026-64952MEDIUM6.5The hunt_delete() VQL function allows deleting hunts.  Velociraptor misapplied the permission check requiring only COLL...
CVE-2026-64951LOW3.5A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic...
CVE-2026-18663MEDIUM5.9A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Sess...
CVE-2026-18652MEDIUM4.9Velociraptor allows reading Stacked result sets from the GUI.  Velociraptor's multi-tenant design stores sub orgs within...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now