2026 CVE Vulnerabilities

50,977 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-46362HIGH7.1phpMyFAQ before 4.1.2 contains an authorization bypass vulnerability in AbstractAdministrationController::userHasPermiss...
CVE-2026-46361HIGH8.2phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in search.twig where result.question and resu...
CVE-2026-46359HIGH7.7phpMyFAQ before 4.1.2 contains a sql injection vulnerability in CurrentUser::setTokenData that allows authenticated atta...
CVE-2026-45800HIGH8.7Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3...
CVE-2026-45008HIGH7phpMyFAQ before 4.1.2 contains a path traversal vulnerability in Client::deleteClientFolder that allows admins with INST...
CVE-2026-44826HIGH7.5Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.2...
CVE-2026-46474HIGH7.5Trog::TOTP versions before 1.006 for Perl generate secrets using rand. Secrets were generated using Perl's built-in ran...
CVE-2026-45539HIGH7.4Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive ...
CVE-2026-45038HIGH7.8Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, since Tabby does not escape cont...
CVE-2026-45037HIGH7.1Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.232, Tabby's terminal linkifier passe...
CVE-2026-45036HIGH7Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby before 1.0.233 automatical...
CVE-2026-45035HIGH8.8Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby registers itself as the ha...
CVE-2026-44714HIGH7.5The bitcoinj library is a Java implementation of the Bitcoin protocol. Prior to 0.17.1, ScriptExecution.correctlySpends(...
CVE-2026-44641HIGH7.1Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.8.12, Microsoft APM norma...
CVE-2026-46508HIGH7.8Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14000, the Turborepo ...
CVE-2026-35194HIGH8.1Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated u...
CVE-2026-46483HIGH7Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimu...
CVE-2026-45736HIGH7.5ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is v...
CVE-2026-39054HIGH7.3Oinone Pamirs 7.0.0 contains a command injection vulnerability in CommandHelper.executeCommands. The method starts a she...
CVE-2026-38728HIGH7.5An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStr...
CVE-2026-34253HIGH8.2A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in functi...
CVE-2026-46333HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The ...
CVE-2026-41552HIGH7.5PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sani...
CVE-2026-41964HIGH8.4Permission control vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availabili...
CVE-2026-6403HIGH7.5The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now