2026 CVE Vulnerabilities

48,299 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-44914HIGH7.2Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension componen...
CVE-2026-44913HIGH7.2Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2....
CVE-2026-8157HIGH8.8The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new u...
CVE-2026-6858HIGH7.1The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthen...
CVE-2026-4259HIGH7.1The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outp...
CVE-2026-6645HIGH7.3An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy ...
CVE-2026-8918HIGH7.1A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/...
CVE-2026-11745HIGH8.8A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH...
CVE-2026-12822HIGH7.8A vulnerability was identified in langflow-ai langflow up to 1.9.3. This affects an unknown function of the component Bu...
CVE-2026-12806HIGH8.8A vulnerability has been found in Edimax BR-6478AC V2 1.23. The impacted element is the function formWlSiteSurvey of the...
CVE-2026-56396HIGH8.8phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that...
CVE-2026-56394HIGH7.1Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the ex...
CVE-2026-56382HIGH8.6Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability ...
CVE-2026-56378HIGH8.2ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage...
CVE-2026-56253HIGH8.7Capgo before 12.128.2 contains an improper access control vulnerability in the public.get_org_members RPC function that ...
CVE-2026-56251HIGH7Capgo before 12.128.2 contains a broken row level security policy in the org_users table that allows authenticated users...
CVE-2026-56242HIGH8.7Capgo before 12.128.2 contains an unauthenticated security definer RPC function get_identity_apikey_only that returns th...
CVE-2026-56239HIGH7.6Capgo before 12.128.2 contains a potential privilege escalation vulnerability in the public.apply_usage_overage SECURITY...
CVE-2026-56229HIGH7.1Capgo before 12.128.2 contains an authorization bypass vulnerability in the /build/status and /build/logs endpoints that...
CVE-2026-12795HIGH7.3A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm...
CVE-2026-12786HIGH7.8A vulnerability has been found in Ezbsystems UltraISO Premium Edition up to 9.76. Affected by this issue is some unknown...
CVE-2026-52911HIGH8.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: scope conn->binding slowpath to bound sessio...
CVE-2026-12784HIGH7.8A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown function in the librar...
CVE-2026-12782HIGH7.8A security flaw has been discovered in EaseUS Partition Master up to 14.5. The impacted element is an unknown function i...
CVE-2026-12781HIGH7.8A vulnerability was identified in EaseUS Partition Master up to 14.5. The affected element is an unknown function in the...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now