2026 CVE Vulnerabilities

48,557 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-45549HIGH8.5Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ag...
CVE-2026-9758HIGH7.3Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untrusted certificate to ...
CVE-2026-53435HIGH8.8In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrar...
CVE-2026-52758HIGH8.8Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values dir...
CVE-2026-52755HIGH8.4Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that allows attackers to ...
CVE-2026-52754HIGH8.8Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows...
CVE-2026-52752HIGH8.4Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry...
CVE-2026-52751HIGH8.8Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code th...
CVE-2026-52750HIGH8.4Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metach...
CVE-2026-49498HIGH8.8Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabas...
CVE-2026-49069HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio a...
CVE-2026-24067HIGH8.4Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.too...
CVE-2026-24066HIGH8.4Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.too...
CVE-2026-3018HIGH7.5The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in ...
CVE-2026-10721HIGH8.4Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the  in Permission, Cache, and...
CVE-2026-8071HIGH8.8The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a cus...
CVE-2026-3326HIGH8.6The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL state...
CVE-2026-29116HIGH8.7A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially...
CVE-2026-10846HIGH7.5NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks m...
CVE-2026-11837HIGH7.3A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() ...
CVE-2026-26239HIGH8.1A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, t...
CVE-2026-26237HIGH7.5A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vul...
CVE-2026-24724HIGH8.1An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user a...
CVE-2026-24719HIGH7.2A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack...
CVE-2026-24716HIGH7.2A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now