2026 CVE Vulnerabilities

47,701 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-7831HIGH7.6UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit message handler. In v...
CVE-2026-7830HIGH7.4UltraVNC through 1.8.2.2 uses inadequate cryptography in the MS-Logon II authentication scheme (rfbUltraVNC_MsLogonIIAut...
CVE-2026-7829HIGH7.2UltraVNC repeater through 1.8.2.2 contains a post-authentication out-of-bounds write in the allow/deny rule parser. In r...
CVE-2026-7517HIGH7.2The Custom Payment Gateways for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'a...
CVE-2026-13731HIGH7.2The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross...
CVE-2026-13468HIGH7.5The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to authorization ...
CVE-2026-12923HIGH7.5The Youtube Showcase plugin for WordPress is vulnerable to Arbitrary Function Call in versions up to and including 4.0.3...
CVE-2026-20458HIGH7.5In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote escalation of p...
CVE-2026-14191HIGH7.8An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeade...
CVE-2026-53488HIGH8.8containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plu...
CVE-2026-54592HIGH7.5Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj::Doc#...
CVE-2026-57995HIGH8.8phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GR...
CVE-2026-56361HIGH7.1ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer rea...
CVE-2026-56350HIGH7.7n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforce...
CVE-2026-56328HIGH7.1Capgo before 12.128.2 allows multiple public channels for the same app and platform to coexist simultaneously, while unn...
CVE-2026-56320HIGH7.1Capgo before 12.128.2 contains an authorization flaw in POST /private/create_device that accepts a caller-supplied org_i...
CVE-2026-56300HIGH8.7Capgo before 12.128.2 contains unauthenticated security definer RPC functions get_user_id and get_org_perm_for_apikey th...
CVE-2026-56286HIGH8.1Capgo before 12.128.2 contains an authentication bypass vulnerability in the account deletion endpoint that allows delet...
CVE-2026-56249HIGH7.6Capgo before 12.128.2 contains an authorization bypass vulnerability in the channel creation endpoint that allows authen...
CVE-2026-56247HIGH8.8Capgo before 12.128.2 allows org admins to assign org-scoped RBAC roles at app scope without validating role scope compa...
CVE-2026-56233HIGH8.7Capgo before 12.128.2 contains a path traversal vulnerability in the builder upload proxy that allows authenticated user...
CVE-2026-56230HIGH8.8Capgo before 12.128.2 contains a broken object level authorization vulnerability in middlewareKey() that accepts the cli...
CVE-2026-56219HIGH8.7Capgo before 12.128.2 contains a NULL-auth bypass vulnerability in the public.get_org_user_access_rbac function that all...
CVE-2026-54673HIGH8.2electron-updater allows for automatic updates for Electron apps. Prior to 9.7.0, the HTTP redirect handler (HttpExecutor...
CVE-2026-54672HIGH7.8electron-updater allows for automatic updates for Electron apps. Prior to 26.15.0, AppImage targets built by app-builder...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now