2026 CVE Vulnerabilities

48,516 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-39590HIGH8.1Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions.
CVE-2026-39576HIGH8.1Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.
CVE-2026-39560HIGH8.1Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.
CVE-2026-39559HIGH8.1Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions.
CVE-2026-39556HIGH8.1Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.
CVE-2026-39523HIGH8.1Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions.
CVE-2026-39445HIGH8.1Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.
CVE-2026-39442HIGH8.1Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.
CVE-2026-10641HIGH7.1Zephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role parser (subsys/bluetooth/host/classic/hfp_hf.c) cont...
CVE-2026-9690HIGH7.5Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions.
CVE-2026-9570HIGH7.1The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inline ...
CVE-2026-8089HIGH7.1The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin ...
CVE-2026-5667HIGH7.2Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); ...
CVE-2026-55706HIGH8.3sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values f...
CVE-2026-54805HIGH8.8Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions.
CVE-2026-54804HIGH7.6Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions.
CVE-2026-54802HIGH7.5Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions.
CVE-2026-54195HIGH7.1Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions.
CVE-2026-54192HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions.
CVE-2026-54189HIGH7.1Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
CVE-2026-54188HIGH7.1Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
CVE-2026-54185HIGH8.5Subscriber SQL Injection in Cornerstone < 7.8.8 versions.
CVE-2026-54184HIGH8.2Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions.
CVE-2026-53876HIGH8.6RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbitrary c...
CVE-2026-52698HIGH7.4Subscriber Sensitive Data Exposure in PushEngage – Web Push Notifications, eCommerce Automation &amp; Chat Widget <= 4.2...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now