2026 CVE Vulnerabilities

48,099 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-54845HIGH8.1Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions.
CVE-2026-54844HIGH7.5Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions.
CVE-2026-54842HIGH8.1Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control S...
CVE-2026-54841HIGH7.5Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions.
CVE-2026-54838HIGH8.5Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions.
CVE-2026-54830HIGH7.5Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions.
CVE-2026-54829HIGH7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt...
CVE-2026-54828HIGH7.5Unauthenticated Broken Access Control in Motors <= 1.4.109 versions.
CVE-2026-54822HIGH8.5Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.
CVE-2026-54821HIGH7.4Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.
CVE-2026-49506HIGH7.2Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted ...
CVE-2026-47151HIGH7.1In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock...
CVE-2026-47150HIGH7.1In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write a...
CVE-2026-47147HIGH7.1In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limi...
CVE-2026-46734HIGH7.8Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Certificate Validation vulner...
CVE-2026-46733HIGH7.8Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, contain an Improper Access Control vulnerabil...
CVE-2026-46732HIGH7Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain a Concurrent Execution using Shared Resou...
CVE-2026-2815HIGH8.4Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys
CVE-2026-27366HIGH7.5Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions.
CVE-2026-33612HIGH7.5A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning.
CVE-2026-56091HIGH8.2When using Apache Shiro with the shiro-guice module in a web servlet context, a specially crafted HTTP request may cause...
CVE-2026-53277HIGH8.8In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Take the SRCU lock for page table walks...
CVE-2026-53276HIGH7.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix a use-after-free of the hci_con...
CVE-2026-53275HIGH8.8In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Fix use-after-free when processing MLD...
CVE-2026-53273HIGH7.8In the Linux kernel, the following vulnerability has been resolved: tee: optee: prevent use-after-free when the client ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now