2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-72578HIGH8.8A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attacker to...
CVE-2026-72573HIGH8.8An OS command injection vulnerability in 4xmen/pm2panel (all versions) allows an authenticated remote attacker to execut...
CVE-2026-72572HIGH7.5A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated remote attacker to read and down...
CVE-2026-72571HIGH7.5A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an unauthenticated remote attacker t...
CVE-2026-72568HIGH7.1An out-of-bounds read vulnerability in Redis through 8.8.1 allows an adjacent unauthenticated attacker to cause denial o...
CVE-2026-72566HIGH7.7A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a low-privileged authent...
CVE-2026-65948HIGH7.3UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.  Note:  UnixAuth is NOT a recommended option f...
CVE-2026-65942HIGH7.5TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to upgrade to v...
CVE-2026-61899HIGH7.5Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets v...
CVE-2026-59087HIGH7.8A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote...
CVE-2026-55814HIGH7.5Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version ...
CVE-2026-44630HIGH7.5Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to caus...
CVE-2026-66407HIGH8.1DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket privat...
CVE-2026-66405HIGH8.8DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to th...
CVE-2026-66403HIGH8.7DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log informatio...
CVE-2026-21079HIGH7Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept tr...
CVE-2026-21074HIGH7.2Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands wi...
CVE-2026-21068HIGH8.4Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execut...
CVE-2026-21064HIGH7Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.
CVE-2026-64940HIGH8.8Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular exp...
CVE-2026-19049HIGH8.6The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries,...
CVE-2026-18946HIGH7.5The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded thr...
CVE-2026-18786HIGH8.8The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and ...
CVE-2026-18470HIGH7.5The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the a...
CVE-2026-18469HIGH8.1The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a se...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now