2026 CVE Vulnerabilities

50,938 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-71201MEDIUM5In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assign...
CVE-2026-70375HIGH8.8HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDe...
CVE-2026-70374HIGH8.8HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail genera...
CVE-2026-68080MEDIUM6.5It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated atta...
CVE-2026-68078MEDIUM6.5It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att...
CVE-2026-68077MEDIUM6.5An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to ...
CVE-2026-68075MEDIUM6.5An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service...
CVE-2026-68073HIGH7.5A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of...
CVE-2026-67592HIGH7.5It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att...
CVE-2026-67591MEDIUM6.5An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service...
CVE-2026-67590HIGH7.5A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of...
CVE-2026-67555MEDIUM6.5It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att...
CVE-2026-67554MEDIUM6.5An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to ...
CVE-2026-67553MEDIUM6.5An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service...
CVE-2026-67552HIGH7.5A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of...
CVE-2026-66277MEDIUM6.5It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att...
CVE-2026-66276MEDIUM6.5An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to ...
CVE-2026-66275MEDIUM6.5An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service...
CVE-2026-66274HIGH7.5A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of...
CVE-2026-49004MEDIUM6.5The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabi...
CVE-2026-17515MEDIUM4.3The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisatio...
CVE-2026-16993LOW3.7The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage direc...
CVE-2026-16981MEDIUM5.3The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capa...
CVE-2026-16968MEDIUM6.5The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users...
CVE-2026-16942MEDIUM5.4The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page hand...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now