2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-54209HIGH8.9Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by including t...
CVE-2026-54208HIGH8.5Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated...
CVE-2026-54204HIGH7.7Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set t...
CVE-2026-54202HIGH8.5Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation funct...
CVE-2026-54200HIGH8.4Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax,...
CVE-2026-12070HIGH8.4Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability in the send email, ...
CVE-2026-9169HIGH8.8DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitr...
CVE-2026-66491HIGH8.2Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the g...
CVE-2026-49007HIGH7.5By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for th...
CVE-2026-19196HIGH7.3A vulnerability was found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the ...
CVE-2026-16263HIGH8.8The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not p...
CVE-2026-16262HIGH7.5The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating...
CVE-2026-16041HIGH7.5The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST p...
CVE-2026-16030HIGH8.1The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used t...
CVE-2026-15361HIGH8.1The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does n...
CVE-2026-15215HIGH8.8The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing ...
CVE-2026-14943HIGH7.5The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 d...
CVE-2026-19195HIGH7.8A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in th...
CVE-2026-19193HIGH7.8A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys...
CVE-2026-19192HIGH7.8A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C...
CVE-2026-19191HIGH7.8A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code o...
CVE-2026-19190HIGH7.8A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Fil...
CVE-2026-49746HIGH7.1Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memor...
CVE-2026-45198HIGH7.8Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause G...
CVE-2026-19189HIGH7.8A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functional...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now