2026 CVE Vulnerabilities

50,971 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-47784HIGH8.1In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because me...
CVE-2026-47783HIGH8.1In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a ...
CVE-2026-9057HIGH8.2A broken access control issue has been identified in the Talend Administration Center, that allows a user with “View” pe...
CVE-2026-7522HIGH8.8The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion in versions up to, an...
CVE-2026-9010HIGH7.5The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameter...
CVE-2026-9003HIGH8.7E-LAN Hybrid Recording System developed by TONNET has a SQL Injection vulnerability, allowing unauthenticated remote att...
CVE-2026-7460HIGH7.4mailcow-dockerized contains a stored cross-site scripting vulnerability in the administrator Queue Manager. The Queue Ma...
CVE-2026-24215HIGH7.5NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, where an attacker could cause uncontrolled ...
CVE-2026-24210HIGH7.5NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an integer overflow. A successful ...
CVE-2026-24209HIGH7.5NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successf...
CVE-2026-24208HIGH7.5NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successf...
CVE-2026-24160HIGH7.5NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked return value to a n...
CVE-2026-7467HIGH8.8The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin...
CVE-2026-6456HIGH8.8The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1....
CVE-2026-43619HIGH7.2Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod,...
CVE-2026-43618HIGH8.1Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit s...
CVE-2026-3985HIGH7.5The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection v...
CVE-2026-34463HIGH8.6Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior contain a Stored XSS vulnerabil...
CVE-2026-34358HIGH8.1CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contains a broken access contr...
CVE-2026-34241HIGH8.7CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Sc...
CVE-2026-39250HIGH7.3An authorization vulnerability exists in Innoshop 0.6.0. After logging into the frontend, an attacker can directly acces...
CVE-2026-32882HIGH7.1libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in...
CVE-2026-32741HIGH7.1libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in ...
CVE-2026-32740HIGH8.8libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (wr...
CVE-2026-27173HIGH8.7JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kube...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now