2026 CVE Vulnerabilities

48,012 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-56285HIGH8.6Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded defaul...
CVE-2026-36848HIGH7.5Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.
CVE-2026-13592HIGH7.3A vulnerability was detected in liftoff-sr CIPster up to e8e9dba09bf56962807d3504b783ccdb6287f3e4. Affected by this issu...
CVE-2026-13752HIGH8Improper neutralization of parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. An attac...
CVE-2026-12912HIGH7.3A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLo...
CVE-2026-41052HIGH8.8Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2...
CVE-2026-13749HIGH8.8Improper neutralization in the Snowpark annotation processor callback template in Snowflake CLI versions prior to 3.19 a...
CVE-2026-13744HIGH8.8Improper neutralization of attacker-controlled content in Snowflake CLI versions prior to 3.19 allowed unintended SQL ex...
CVE-2026-13583HIGH8.8A vulnerability has been found in Edimax EW-7478APC 1.04. Impacted is the function formUSBFolder of the file /goform/for...
CVE-2026-13582HIGH8.8A flaw has been found in Edimax EW-7478APC 1.04. This issue affects the function formUSBAccount of the file /goform/form...
CVE-2026-13580HIGH8.8A security vulnerability has been detected in Edimax EW-7478APC 1.04. This affects the function formQoS of the file /gof...
CVE-2026-57338HIGH7.1Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions.
CVE-2026-57337HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions.
CVE-2026-57336HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Jobify <= 4.3.2 versions.
CVE-2026-57333HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free <= 0.9.4 versions.
CVE-2026-57332HIGH7.1Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.
CVE-2026-57320HIGH7.1Unauthenticated Cross Site Scripting (XSS) in BEAR <= 1.1.8 versions.
CVE-2026-56124HIGH8.7phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers t...
CVE-2026-55844HIGH7.5Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The...
CVE-2026-55607HIGH8.8Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of w...
CVE-2026-49049HIGH7.5The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary fil...
CVE-2026-54371HIGH7.1attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows ...
CVE-2026-54370HIGH7.2acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local...
CVE-2026-54369HIGH7.1acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(...
CVE-2026-40524HIGH8.1FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the get_gl_transactions() function where the fil...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now