2026 CVE Vulnerabilities

49,581 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-47201HIGH8.5authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Sou...
CVE-2026-10620HIGH7.3A flaw has been found in code-projects Student Admission System 1.0. Affected is an unknown function of the file /index....
CVE-2026-10619HIGH7.3A vulnerability was detected in sayan365 student-management-system up to 7f3c9ce7d410332335c2affac93a385485051800. This ...
CVE-2026-8036HIGH7.8Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially ...
CVE-2026-5385HIGH8.4An unauthenticated user with write access to the knowledge base can store an XSS payload in a knowledge base item. Thi...
CVE-2026-5073HIGH7.5The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'arm_directory...
CVE-2026-49120HIGH8.5Medplum before 5.1.14 contains a server-side request forgery vulnerability in the subscription worker that allows authen...
CVE-2026-48594HIGH7.5Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-tesla tesla allows a denial of ...
CVE-2026-47265HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set wit...
CVE-2026-42342HIGH7.5React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 ...
CVE-2026-42211HIGH8.1React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps ...
CVE-2026-41577HIGH7.5authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response proces...
CVE-2026-34993HIGH7.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJ...
CVE-2026-34077HIGH7.5React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Co...
CVE-2026-28299HIGH7.5SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause...
CVE-2026-1829HIGH8.8The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up t...
CVE-2026-10701HIGH7.5Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 151.0.3.
CVE-2026-10617HIGH7.3A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. This affects the function resolveAut...
CVE-2026-10608HIGH7.3A security flaw has been discovered in DedeCMS 5.7.88. This affects the function RemoveXSS of the file /plus/carbuyactio...
CVE-2026-10607HIGH7.3A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede_htmlspecialchars of the file...
CVE-2026-10584HIGH8.2Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, which might allow rem...
CVE-2026-40715HIGH7.8Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privile...
CVE-2026-24237HIGH7.8NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A su...
CVE-2026-24221HIGH7.8NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A su...
CVE-2026-10606HIGH7.3A vulnerability was determined in DedeCMS 5.7.88. The affected element is the function TrimMsg of the file /plus/feedbac...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now