2026 CVE Vulnerabilities

48,099 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-57456HIGH7.8Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/pytho...
CVE-2026-57455HIGH7.8Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in ...
CVE-2026-57453HIGH7.3Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip....
CVE-2026-55895HIGH7.8Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s...
CVE-2026-55693HIGH7.8Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c f...
CVE-2026-55477HIGH7.23X-UI is a web control panel for managing Xray-core servers. Prior to 3.3.1, an authenticated administrator can abuse th...
CVE-2026-54036HIGH8.1LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the GET /api/auth/2fa/en...
CVE-2026-12844HIGH7.5List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow in the pairwise function. pairwise() coll...
CVE-2026-57532HIGH8.8Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF ...
CVE-2026-57435HIGH7.5Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri’s CRuby nat...
CVE-2026-57434HIGH7.5Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri contains a ...
CVE-2026-57236HIGH8.2Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, calling Document#enc...
CVE-2026-57235HIGH8.2Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::NodeS...
CVE-2026-46735HIGH7.8Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Neutralization of Special Ele...
CVE-2026-56122HIGH8.7Winstone Servlet Engine through 0.9.10 contains a path traversal vulnerability that allows unauthenticated attackers to ...
CVE-2026-56071HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions.
CVE-2026-56054HIGH7.7Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions.
CVE-2026-56053HIGH8.8Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.
CVE-2026-56051HIGH7.1Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions.
CVE-2026-56049HIGH8.5Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions.
CVE-2026-56042HIGH7.1Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions.
CVE-2026-56014HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions.
CVE-2026-56006HIGH7.1Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions.
CVE-2026-56005HIGH7.1Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions.
CVE-2026-54848HIGH8.3Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows R...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now