2026 CVE Vulnerabilities

48,876 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-7654HIGH8.8The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in version...
CVE-2026-11431HIGH8.3A path traversal vulnerability exists in the Projects Service download endpoint shared by Altium Enterprise Server and A...
CVE-2026-11424HIGH8.3A server-side request forgery (SSRF) vulnerability exists in a GraphQL service component shared by Altium Enterprise Ser...
CVE-2026-11416HIGH8.1MoviePilot contains a path traversal vulnerability in the AliPan, U115, and Rclone cloud storage download handlers where...
CVE-2026-36785HIGH7.5Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the page parameter...
CVE-2026-11422HIGH8.4Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom ren...
CVE-2026-46493HIGH7.5HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.1 use `uniqid` for generatin...
CVE-2026-46400HIGH8.7HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 11.0.6 and prior to version 25....
CVE-2026-46398HIGH8.8HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 25.0.0 and prior to version 26....
CVE-2026-45300HIGH7.4The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT...
CVE-2026-25623HIGH7An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge Threat Mana...
CVE-2026-25622HIGH7A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Ge...
CVE-2026-25621HIGH7A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Generation Fire...
CVE-2026-25620HIGH7An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge ...
CVE-2026-11419HIGH8.8A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improper val...
CVE-2026-11401HIGH8.6An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL w...
CVE-2026-11400HIGH8.6An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL...
CVE-2026-5415HIGH8.8The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for Wor...
CVE-2026-5411HIGH8.8The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for Wor...
CVE-2026-46511HIGH8.7HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an attack chain utilizing ...
CVE-2026-46394HIGH7.7HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an OS command injection vu...
CVE-2026-46393HIGH7.1HAX CMS helps manage microsite universe with PHP or NodeJs backends. An authenticated Server-Side Request Forgery (SSRF)...
CVE-2026-46392HIGH8.7HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFi...
CVE-2026-46391HIGH8.7HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 9.0.1 and prior to version 26.0...
CVE-2026-50733HIGH8.8Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown content with eval(), a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now