2026 CVE Vulnerabilities

50,974 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-26978HIGH8.6FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize dat...
CVE-2026-22810HIGH7.3Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior...
CVE-2026-47092HIGH7.8Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attac...
CVE-2026-45245HIGH7.4Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch ...
CVE-2026-45242HIGH7.1Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows authe...
CVE-2026-29963HIGH7.5HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input in the /t...
CVE-2026-29962HIGH7.5HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-suppli...
CVE-2026-8843HIGH7.1Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subsequent attempt to ins...
CVE-2026-41085HIGH8.8Thermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability that may allow an auth...
CVE-2026-41949HIGH7.5Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any a...
CVE-2026-39079HIGH7.5An issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker to obtain sensitive info...
CVE-2026-26462HIGH7.3Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron renderer configuration...
CVE-2026-42009HIGH7.5A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) pac...
CVE-2026-0983HIGH7.1Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 all...
CVE-2026-7498HIGH8.8Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Informatio...
CVE-2026-6902HIGH7.7A Remote Code Execution vulnerability in P4 (Helix Core) Server's Command-Line Client, prior to the 2025.2 Patch 2, has ...
CVE-2026-6347HIGH7.6Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fie...
CVE-2026-6346HIGH8.7Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fie...
CVE-2026-8788HIGH7.3Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections. The values from the set_add method were n...
CVE-2026-6495HIGH7.1The Ajax Load More WordPress plugin before 7.8.4 does not sanitise and escape a parameter before outputting it back in ...
CVE-2026-6381HIGH7.5The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowi...
CVE-2026-6379HIGH8.6The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a parameter before usin...
CVE-2026-3220HIGH8.8The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress...
CVE-2026-8785HIGH7.3A flaw has been found in projectworlds hospital-management-system-in-php 1.0. Affected by this vulnerability is the func...
CVE-2026-8776HIGH8.8A vulnerability has been found in Edimax BR-6428NS 1.10. This vulnerability affects the function formPPTPSetup of the fi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now