2026 CVE Vulnerabilities

50,911 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-40848HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the tag view due to impr...
CVE-2026-40847HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system_tag view due ...
CVE-2026-40846HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system view due to i...
CVE-2026-40845HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the devices_configuratio...
CVE-2026-40844HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dashboard view due t...
CVE-2026-40843HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the alarming view due to...
CVE-2026-40842HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getWidgetTags functi...
CVE-2026-40841HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectTags funct...
CVE-2026-40840HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the VerifyCreateLicences...
CVE-2026-40839HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getComponentScalings...
CVE-2026-40838HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getDeviceScalings fu...
CVE-2026-40837HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectScalings f...
CVE-2026-40836HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the inmessage model due ...
CVE-2026-40835HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the saveObjectFromData f...
CVE-2026-40834HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dash_layout.php file...
CVE-2026-40833HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dash.php files saveD...
CVE-2026-40832HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getDevicegroups func...
CVE-2026-40831HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the Easy View due to imp...
CVE-2026-40830HIGH7A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the admin.mbnetj.php fil...
CVE-2026-40829HIGH7A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the view.html.php files ...
CVE-2026-40828HIGH7A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DeleteSysLogEntry fu...
CVE-2026-40827HIGH7A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _RemoveRequest funct...
CVE-2026-8832HIGH8.8The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for WordPress is vulnerab...
CVE-2026-8143HIGH7.2The HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hb_country_iso', 'hb_usa_state_iso'...
CVE-2026-6169HIGH7.2The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now