2026 CVE Vulnerabilities

48,851 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-11456HIGH7.3A vulnerability was identified in Chanjet CRM 1.0. This affects an unknown part of the file /tools/jxf_dump_systable.php...
CVE-2026-11452HIGH7.3A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function FUN_0042e200 of the file /cgi-...
CVE-2026-11451HIGH7.3A flaw has been found in GL.iNet GL-MT3000 4.4.5. This impacts the function snprintf of the file /cgi-bin/glc of the com...
CVE-2026-11450HIGH7.3A vulnerability was detected in GL.iNet GL-MT3000 4.4.5. This affects the function dlopen in the library /usr/lib/oui-ht...
CVE-2026-26422HIGH8.4clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, leading to local privilege escalation.
CVE-2026-11437HIGH7.3A flaw has been found in perfree go-fastdfs-web up to 1.3.7. Affected is the function checkServer of the file /install/c...
CVE-2026-11435HIGH7.3A security vulnerability has been detected in Jinher OA 1.0. This affects an unknown function of the file nextselectplan...
CVE-2026-11413HIGH8.8A security vulnerability has been detected in JingDong JD Cloud Box AX6600 4.5.3.r4546. The impacted element is the func...
CVE-2026-10725HIGH7.5Protocol::HTTP2 versions before 1.13 for Perl is vulnerable to a HTTP/2 Bomb. Protocol::HTTP2's inbound HPACK path has ...
CVE-2026-9851HIGH7.2The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, a...
CVE-2026-7537HIGH7.2The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and includi...
CVE-2026-8901HIGH7.2The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vuln...
CVE-2026-8438HIGH7.2The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2026-9290HIGH7.5The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in al...
CVE-2026-34123HIGH7On Tapo C520WS v2, restricted accounts (for example, hub users) are intended to execute only a limited set of low‑sensit...
CVE-2026-7654HIGH8.8The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in version...
CVE-2026-11431HIGH8.3A path traversal vulnerability exists in the Projects Service download endpoint shared by Altium Enterprise Server and A...
CVE-2026-11424HIGH8.3A server-side request forgery (SSRF) vulnerability exists in a GraphQL service component shared by Altium Enterprise Ser...
CVE-2026-11416HIGH8.1MoviePilot contains a path traversal vulnerability in the AliPan, U115, and Rclone cloud storage download handlers where...
CVE-2026-36785HIGH7.5Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the page parameter...
CVE-2026-11422HIGH8.4Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom ren...
CVE-2026-46493HIGH7.5HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.1 use `uniqid` for generatin...
CVE-2026-46400HIGH8.7HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 11.0.6 and prior to version 25....
CVE-2026-46398HIGH8.8HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 25.0.0 and prior to version 26....
CVE-2026-45300HIGH7.4The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now