2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-17191CRITICAL9.1An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this...
CVE-2026-66398CRITICAL9.4phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated...
CVE-2026-66396CRITICAL9.3SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cov...
CVE-2026-66395CRITICAL9.6SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler...
CVE-2026-66394CRITICAL9.3SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows ...
CVE-2026-16812CRITICAL10VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privile...
CVE-2026-59550CRITICAL9.3Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.
CVE-2026-59549CRITICAL9.3Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
CVE-2026-59538CRITICAL9.3Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
CVE-2026-59533CRITICAL9.3Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.
CVE-2026-59527CRITICAL9.3Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-65879CRITICAL9.8Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder <...
CVE-2026-65876CRITICAL9.2Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Improper validation of c...
CVE-2026-65766CRITICAL9.2Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of o...
CVE-2026-61511CRITICAL9.8vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::...
CVE-2026-58662CRITICAL9.1Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. Thi...
CVE-2026-58023CRITICAL9.1Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Us...
CVE-2026-55971CRITICAL9.8Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0...
CVE-2026-48144CRITICAL9.1Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affect...
CVE-2026-64535CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch S...
CVE-2026-64534CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_unini...
CVE-2026-14289CRITICAL9The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request hand...
CVE-2026-13714CRITICAL9.8The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded f...
CVE-2026-13597CRITICAL9.1The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check alwa...
CVE-2026-13332CRITICAL9.1The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX acti...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now