2026 CVE Vulnerabilities

43,031 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-66150HIGH7.8Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows...
CVE-2026-66149HIGH7.8Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows...
CVE-2026-63177HIGH7.1Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Ng...
CVE-2026-55676HIGH8.8Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `P...
CVE-2026-48763HIGH8.2TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/t...
CVE-2026-15606HIGH8.8The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i...
CVE-2026-14863HIGH8.8FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated at...
CVE-2026-73242HIGH8.3FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos...
CVE-2026-73241HIGH8.3FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreer...
CVE-2026-73234HIGH7.8FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() i...
CVE-2026-73233HIGH8.5FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the FEM Displacement Constraint t...
CVE-2026-73232HIGH7.5ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory...
CVE-2026-73231HIGH7.8Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method ...
CVE-2026-73031HIGH8.7telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary J...
CVE-2026-71467HIGH7.5A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authent...
CVE-2026-48813HIGH8.7Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have a...
CVE-2026-48804HIGH7.5python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server store...
CVE-2026-19091HIGH8.1The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to ...
CVE-2026-18844HIGH8.1The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (...
CVE-2026-13457HIGH7.5The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all ...
CVE-2026-73227HIGH8.1electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al...
CVE-2026-73226HIGH8.8electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm al...
CVE-2026-73225HIGH8.1electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al...
CVE-2026-73224HIGH8.8electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al...
CVE-2026-73223HIGH8.1electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now