2026 CVE Vulnerabilities

48,299 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-12780HIGH7.8A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown function in the library amwrtdrv.s...
CVE-2026-12779HIGH7.8A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. This issue affects some unknown processing in the...
CVE-2026-12778HIGH7.8A vulnerability has been found in AOMEI Partition Assistant up to 10.10.1. This vulnerability affects unknown code in th...
CVE-2026-12775HIGH7.3A vulnerability was detected in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. Affecte...
CVE-2026-12771HIGH7.5A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/pro...
CVE-2026-12770HIGH8.8A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file ...
CVE-2026-56341HIGH8.7AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authori...
CVE-2026-56340HIGH7.5vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because P...
CVE-2026-11912HIGH7.5The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization...
CVE-2026-11911HIGH7.5The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat...
CVE-2026-9843HIGH8.1The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion ...
CVE-2026-56216HIGH8.8Capgo before 12.128.2 contains a scope escalation vulnerability in the POST /functions/v1/apikey endpoint that allows ap...
CVE-2026-56215HIGH8.7Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbitrary addresses, whi...
CVE-2026-56214HIGH8.7Capgo before 12.128.2 contains an information disclosure vulnerability in Supabase PostgREST RPC endpoints is_trial_org ...
CVE-2026-56082HIGH8.7Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST...
CVE-2026-56079HIGH7.1Capgo before 12.128.2 contains a cross-tenant authorization bypass vulnerability in PostgREST endpoints that allows org-...
CVE-2026-50559HIGH7.5Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, ...
CVE-2026-50519HIGH7.5Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized at...
CVE-2026-49346HIGH7.1libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream wi...
CVE-2026-49295HIGH7.1libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream c...
CVE-2026-48584HIGH8.8Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a networ...
CVE-2026-47645HIGH8.8Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized atta...
CVE-2026-42895HIGH7.5Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut...
CVE-2026-49344HIGH7.1Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, ...
CVE-2026-48787HIGH7.4gin-vue-admin is an AI-assisted basic development platform. In version 2.9.1, an authenticated attacker with access to t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now