2026 CVE Vulnerabilities

43,274 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-71190HIGH8.7In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to cat...
CVE-2026-68074HIGH7.5A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni...
CVE-2026-68060HIGH7.5A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential...
CVE-2026-67589HIGH7.5A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential...
CVE-2026-67588HIGH7.5A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni...
CVE-2026-67551HIGH7.5pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential d...
CVE-2026-67465HIGH7.5A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni...
CVE-2026-66839HIGH8.4NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerabil...
CVE-2026-66273HIGH7.5A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential...
CVE-2026-66257HIGH7.5A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni...
CVE-2026-55707HIGH7.1In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An au...
CVE-2026-18902HIGH7.3A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/...
CVE-2026-18322HIGH8.8The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu...
CVE-2026-16143HIGH7.2The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2026-15918HIGH7.5VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of t...
CVE-2026-18901HIGH7.3A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/e...
CVE-2026-18900HIGH7.3A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the co...
CVE-2026-18898HIGH8.8A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the fil...
CVE-2026-18907HIGH7.5Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via direc...
CVE-2026-18897HIGH8.8A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strc...
CVE-2026-18895HIGH8.8A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /go...
CVE-2026-18859HIGH7.3A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/u...
CVE-2026-46334HIGH8.7OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a d...
CVE-2026-45809HIGH8.7OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a d...
CVE-2026-18854HIGH7.3A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now