2026 CVE Vulnerabilities

50,941 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-9284HIGH8.2The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information di...
CVE-2026-6898HIGH8.8The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2026-6897HIGH8.8The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2026-6895HIGH8.8The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclos...
CVE-2026-6419HIGH8.8The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up ...
CVE-2026-45659HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-42827HIGH7.5Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz...
CVE-2026-41104HIGH7.5Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose inform...
CVE-2026-40411HIGH8.8Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.
CVE-2026-35430HIGH8.8Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized atta...
CVE-2026-26147HIGH7.7Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
CVE-2026-23663HIGH7.5Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-41147HIGH8.7NukeViet CMS is a multi Content Management System. Versions 4.5.07 and prior contain a Stored Cross-Site Scripting (XSS)...
CVE-2026-41076HIGH8.1RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 t...
CVE-2026-41075HIGH8.8RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through ...
CVE-2026-41074HIGH7.1RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Si...
CVE-2026-41071HIGH8.1libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file w...
CVE-2026-3294HIGH8.8An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjac...
CVE-2026-5843HIGH8.6The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and exe...
CVE-2026-5817HIGH8.6The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loadin...
CVE-2026-40607HIGH7.5Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.11.0 through 2.28.1, a Stored XSS vulnerabi...
CVE-2026-40597HIGH7.6Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS ...
CVE-2026-40596HIGH7.2Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.11.0 through 2.28.1 allow any authenticated us...
CVE-2026-9291HIGH7.5Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remot...
CVE-2026-6406HIGH8.8The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When EC...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now