2026 CVE Vulnerabilities

48,008 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-50750HIGH7.5Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Foll...
CVE-2026-50734HIGH7.5Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ Al...
CVE-2026-49877HIGH8.1Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can...
CVE-2026-49434HIGH7.5Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker th...
CVE-2026-49432HIGH7.5Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. A remote unauth...
CVE-2026-8141HIGH7.2The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include...
CVE-2026-13149HIGH7.7brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time comple...
CVE-2026-10763HIGH7PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support fr...
CVE-2026-12578HIGH8.4The affected product is vulnerable to a deserialization of untrusted data, which may allow an attacker to execute arbitr...
CVE-2026-56808HIGH8.6DGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which may lead to arb...
CVE-2026-56137HIGH8.4RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads ...
CVE-2026-14164HIGH7.5A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive,...
CVE-2026-12240HIGH8The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat...
CVE-2026-11590HIGH8.6The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sanitize user-supplied array keys b...
CVE-2026-11589HIGH8.8The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not properly validate uploaded files, a...
CVE-2026-58302HIGH8.4rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads s...
CVE-2026-8023HIGH7.5Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, ava...
CVE-2026-51219HIGH7.5A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function of lib60870 v2.3.3 to v2.3.6 allows...
CVE-2026-51218HIGH7.5A heap buffer overflow in the TS7Worker::PerformFunctionWrite() function (/core/s7_server.cpp) of snap7 v1.4.3 allows at...
CVE-2026-51221HIGH7.5A buffer overflow in the Get_Attribute_List function of EIPStackGroup OpENer commit 76b95c allows attackers to cause a D...
CVE-2026-34592HIGH7.7Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-55957HIGH7.3Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate...
CVE-2026-53404HIGH7.3Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first cond...
CVE-2026-41896HIGH7.5Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34597HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now