2026 CVE Vulnerabilities

48,064 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-54826HIGH7.6Subscriber Insecure Direct Object References (IDOR) in SupportCandy <= 3.4.6 versions.
CVE-2026-54824HIGH7.5Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions.
CVE-2026-45257HIGH7.8The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and s...
CVE-2026-30041HIGH7.5An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code...
CVE-2026-57923HIGH7.5In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying pr...
CVE-2026-57921HIGH7.5In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment te...
CVE-2026-57920HIGH7.7Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certai...
CVE-2026-57915HIGH7.3It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized...
CVE-2026-40711HIGH8Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-po...
CVE-2026-57918HIGH7.1libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c d...
CVE-2026-57913HIGH7.5Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transc...
CVE-2026-57912HIGH7.5Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes e...
CVE-2026-11702HIGH7.5Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes. When an objec...
CVE-2026-11625HIGH7.5Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. When an object is in...
CVE-2026-57877HIGH8.6An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier....
CVE-2026-57876HIGH7.5An unauthenticated out-of-bounds write vulnerability exists in onvif.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 an...
CVE-2026-57875HIGH7.5An unauthenticated NULL pointer dereference vulnerability exists in the HTTP request parsing logic of multiple CGI compo...
CVE-2026-57874HIGH7.5An unauthenticated buffer overflow vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V...
CVE-2026-57873HIGH7.5An unauthenticated NULL pointer dereference vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-...
CVE-2026-57872HIGH7.5An unauthenticated directory traversal vulnerability exists in get_fcont.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.1...
CVE-2026-49486HIGH7.5The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p(...
CVE-2026-10835HIGH7.7The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one ...
CVE-2026-10823HIGH7.5The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoints and do...
CVE-2026-8797HIGH8.5An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access t...
CVE-2026-50741HIGH8.8Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now