2026 CVE Vulnerabilities

49,059 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-48681HIGH8.1OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted IS...
CVE-2026-41010HIGH8.7ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "...
CVE-2026-8829HIGH7.5HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. The XS routine backing HTML::E...
CVE-2026-41860HIGH8.8CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpReq...
CVE-2026-41859HIGH7.8A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth heade...
CVE-2026-41858HIGH7.5Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities...
CVE-2026-41011HIGH8.7PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz")...
CVE-2026-10737HIGH7.5The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability ...
CVE-2026-10777HIGH7.3A vulnerability was identified in ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08. Af...
CVE-2026-46447HIGH7.7OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info o...
CVE-2026-22055HIGH8.8Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low p...
CVE-2026-22054HIGH8.8Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with l...
CVE-2026-10771HIGH7.3A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-...
CVE-2026-50033HIGH7.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock D...
CVE-2026-44682HIGH7.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock D...
CVE-2026-44609HIGH7.3Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock D...
CVE-2026-42061HIGH7.3Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected...
CVE-2026-8889HIGH7.5Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) an...
CVE-2026-8888HIGH7.5Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as J...
CVE-2026-8881HIGH7.5Version 3.0.7 of the Securly Chrome Extension uses EVP_BytesToKey key derivation with MD5 and a single iteration for AES...
CVE-2026-8879HIGH7.5Version 3.0.7 of the Securly Chrome Extension dynamically registers content13.min.js as a content script via chrome.scri...
CVE-2026-8878HIGH7.5Version 3.0.7 of the Securly Chrome Extension exposes multiple publicly accessible endpoints that allow unauthenticated ...
CVE-2026-8876HIGH7.3Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in securly.min.js. These key...
CVE-2026-8874HIGH7.1Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules ...
CVE-2026-7888HIGH8.4Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now