2026 CVE Vulnerabilities

43,273 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-71226HIGH7.3Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all subm...
CVE-2026-16022HIGH7.8@oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functionality. The CLI constr...
CVE-2026-71255HIGH8.6nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus client-side recv_read_device_identification_res...
CVE-2026-64582HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap ...
CVE-2026-61891HIGH7.5In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoin...
CVE-2026-46581HIGH7.5In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or ...
CVE-2026-18933HIGH7.2The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-pri...
CVE-2026-71252HIGH8.2toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands, ...
CVE-2026-71245HIGH7.1Mautic's getLeadIdsByFieldValueAction (LeadBundle/Controller/AjaxController.php) reads a field parameter from the reques...
CVE-2026-71243HIGH8.8The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, dest...
CVE-2026-71242HIGH8.3Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership ...
CVE-2026-71241HIGH7.5Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are mi...
CVE-2026-71239HIGH8.1DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template const...
CVE-2026-71236HIGH8.7Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incomi...
CVE-2026-71235HIGH8.8Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-sid...
CVE-2026-71234HIGH7.5Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPubl...
CVE-2026-71233HIGH8.7InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output...
CVE-2026-71232HIGH7.2MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template ...
CVE-2026-60009HIGH8.8In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every...
CVE-2026-12609HIGH7.5In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlug...
CVE-2026-25703HIGH7.3NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authenticatio...
CVE-2026-7693HIGH7.2The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2....
CVE-2026-7520HIGH8.1The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missin...
CVE-2026-7444HIGH8.1The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2026-71215HIGH7.5art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include and ext...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now