2026 CVE Vulnerabilities

50,911 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-71244MEDIUM6.5Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, r...
CVE-2026-71243HIGH8.8The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, dest...
CVE-2026-71242HIGH8.3Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership ...
CVE-2026-71241HIGH7.5Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are mi...
CVE-2026-71240MEDIUM4.3DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or sta...
CVE-2026-71239HIGH8.1DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template const...
CVE-2026-71238CRITICAL9.1DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from ...
CVE-2026-71237CRITICAL9.8Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sa...
CVE-2026-71236HIGH8.7Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incomi...
CVE-2026-71235HIGH8.8Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-sid...
CVE-2026-71234HIGH7.5Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPubl...
CVE-2026-71233HIGH8.7InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output...
CVE-2026-71232HIGH7.2MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template ...
CVE-2026-71231CRITICAL9.8IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decod...
CVE-2026-66747CRITICAL9.8Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across ...
CVE-2026-60009HIGH8.8In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every...
CVE-2026-17578LOW2.3Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D re...
CVE-2026-14574MEDIUM6.5In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` rec...
CVE-2026-14304MEDIUM5.5In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and...
CVE-2026-12609HIGH7.5In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlug...
CVE-2026-44945CRITICAL9.1A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An...
CVE-2026-25703HIGH7.3NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authenticatio...
CVE-2026-15452MEDIUM4.7The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Reflected Cross-Sit...
CVE-2026-0931MEDIUM6.9Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cau...
CVE-2026-8029LOW3.9The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now