2026 CVE Vulnerabilities

50,911 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-40825HIGH7A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view d...
CVE-2026-40824HIGH7A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view u...
CVE-2026-40823HIGH7A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset funct...
CVE-2026-40819HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the sync_data24 task du...
CVE-2026-40818HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24confi_getDevic...
CVE-2026-40817HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAlarmProfiles fu...
CVE-2026-40816HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the mb24alarm.php files...
CVE-2026-40815HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24api_getUserAcc...
CVE-2026-40814HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dataapi.php files _...
CVE-2026-40813HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues funct...
CVE-2026-40812HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues funct...
CVE-2026-40811HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the ssoabstractservice ...
CVE-2026-40810HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the userinfo endpoint d...
CVE-2026-3375HIGH7.2The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1/noti...
CVE-2026-9200HIGH7.5The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.2...
CVE-2026-8994HIGH8.1The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0....
CVE-2026-8787HIGH8.8The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in all versions up to,...
CVE-2026-6268HIGH7.1The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eventpress_customizer_n...
CVE-2026-49000HIGH7An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequa...
CVE-2026-48962HIGH7.3IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled ou...
CVE-2026-48961HIGH7.3IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine...
CVE-2026-48959HIGH7.5IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. fastFo...
CVE-2026-2253HIGH7.7Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, d...
CVE-2026-9632HIGH8.8A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the function strcpy of th...
CVE-2026-9631HIGH8.8A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the functi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now