2026 CVE Vulnerabilities

50,938 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-68074HIGH7.5A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni...
CVE-2026-68060HIGH7.5A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential...
CVE-2026-67589HIGH7.5A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential...
CVE-2026-67588HIGH7.5A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni...
CVE-2026-67551HIGH7.5pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential d...
CVE-2026-67465HIGH7.5A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni...
CVE-2026-66839HIGH8.4NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerabil...
CVE-2026-66344MEDIUM5.4NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerabi...
CVE-2026-66273HIGH7.5A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential...
CVE-2026-66257HIGH7.5A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni...
CVE-2026-5062MEDIUM4.9The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPre...
CVE-2026-55707HIGH7.1In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An au...
CVE-2026-18903MEDIUM4.3A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects so...
CVE-2026-18902HIGH7.3A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/...
CVE-2026-18322HIGH8.8The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu...
CVE-2026-16143HIGH7.2The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2026-15941MEDIUM6.5The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches f...
CVE-2026-15918HIGH7.5VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of t...
CVE-2026-11421MEDIUM6.5The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Inje...
CVE-2026-18901HIGH7.3A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/e...
CVE-2026-18900HIGH7.3A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the co...
CVE-2026-18898HIGH8.8A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the fil...
CVE-2026-18907HIGH7.5Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via direc...
CVE-2026-18897HIGH8.8A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strc...
CVE-2026-18896MEDIUM6.3A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown fun...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now