2026 CVE Vulnerabilities

51,054 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-51231Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51230Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51229Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-18446HIGH7.5fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a refer...
CVE-2026-10685HIGH7.6The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked...
CVE-2026-65636LOW2.1Improper Neutralization of CRLF Sequences vulnerability in ufirstgroup ymlr (Elixir.Ymlr module) allows attackers to inj...
CVE-2026-28145MEDIUM5.3Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User ...
CVE-2026-28144MEDIUM4.3Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensiti...
CVE-2026-9611Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-68577Rejected reason: Reserved via standalone CLI outside the OSIM flaw workflow; releasing so the CVE ID can be properly res...
CVE-2026-68576Rejected reason: Reserved via standalone CLI outside the OSIM flaw workflow; releasing so the CVE ID can be properly res...
CVE-2026-68575Rejected reason: Reserved via standalone CLI outside the OSIM flaw workflow; releasing so the CVE ID can be properly res...
CVE-2026-68574Rejected reason: Reserved via standalone CLI outside the OSIM flaw workflow; releasing so the CVE ID can be properly res...
CVE-2026-18358HIGH7.5A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mo...
CVE-2026-17592Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-17561CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Cons...
CVE-2026-15227MEDIUM5.3Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking t...
CVE-2026-46594MEDIUM5.1A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicio...
CVE-2026-46593HIGH8.6A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input...
CVE-2026-64607MEDIUM5.3HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection ma...
CVE-2026-62391HIGH8.1The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend...
CVE-2026-44615MEDIUM6.5Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker wi...
CVE-2026-17567MEDIUM5.3The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne...
CVE-2026-16843HIGH7.2Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validatio...
CVE-2026-18437MEDIUM5.3The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now