2026 CVE Vulnerabilities

64,772 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-94036HIGH8.8A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element i...
CVE-2026-94015HIGH7.3A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the...
CVE-2026-94109HIGH8openEQUELLA before 2026.1.0 contains an authenticated stored server-side template injection vulnerability in FreemarkerP...
CVE-2026-94107HIGH8.1NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that gene...
CVE-2026-94106HIGH8.8getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames ...
CVE-2026-94104HIGH8.8NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails t...
CVE-2026-94004HIGH7.3A vulnerability was found in DedeCMS up to 5.7.118. The affected element is an unknown function of the file plus/mytag_j...
CVE-2026-93997HIGH7.3A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected by this issue is some unknown ...
CVE-2026-93980HIGH7.3A weakness has been identified in code-projects Internship Management System 1.0. This vulnerability affects unknown cod...
CVE-2026-93979HIGH7.3A security flaw has been discovered in code-projects Internship Management System 1.0. This affects an unknown part of t...
CVE-2026-93978HIGH7.3A vulnerability was identified in code-projects Internship Management System 1.0. Affected by this issue is some unknown...
CVE-2026-93974HIGH7.3A flaw has been found in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the f...
CVE-2026-93973HIGH7.3A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown...
CVE-2026-93972HIGH7.3A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element...
CVE-2026-93970HIGH7.3A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the fil...
CVE-2026-93969HIGH7.3A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_default_sup...
CVE-2026-92541HIGH7.2The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in...
CVE-2026-92540HIGH7.2The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users cap...
CVE-2026-87839HIGH7.5The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of t...
CVE-2026-87067HIGH8.5The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deser...
CVE-2026-85017HIGH7.5The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX actio...
CVE-2026-82842HIGH8.1The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming ...
CVE-2026-81650HIGH7.2The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of f...
CVE-2026-93962HIGH8.3A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_...
CVE-2026-86553HIGH8.8SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Us...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now