2026 CVE Vulnerabilities

50,998 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-21019HIGH8.6Improper input validation in FacAtFunction in Galaxy Watch prior to SMR May-2026 Release 1 allows local attacker to exec...
CVE-2026-7635HIGH8.1The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versi...
CVE-2026-8201HIGH8.8A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting clie...
CVE-2026-8199HIGH7.1An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAny...
CVE-2026-8053HIGH8.8An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write priv...
CVE-2026-6888HIGH7.2Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute arbitr...
CVE-2026-8108HIGH7.8The installation of Fuji Tellus adds a driver to the kernel which grants all users read and write permissions.
CVE-2026-5371HIGH7.1The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnera...
CVE-2026-44548HIGH8.1ChurchCRM is an open-source church management system. Prior to 7.3.2, top-level cross-site GET navigation from an attack...
CVE-2026-43685HIGH7.2A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject a...
CVE-2026-43680HIGH7.2A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to bypass a...
CVE-2026-42289HIGH8.8ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and...
CVE-2026-42156HIGH7.1Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri...
CVE-2026-1250HIGH7.5The Court Reservation – Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection vi...
CVE-2026-45227HIGH8.8Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that allows authenticated ...
CVE-2026-45226HIGH7.6Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users ...
CVE-2026-45225HIGH7.6Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows authenticated users t...
CVE-2026-44871HIGH8.8Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS...
CVE-2026-44307HIGH8.7Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\...
CVE-2026-44304HIGH8.1Lemur manages TLS certificate creation. Prior to 1.9.0, Lemur's LDAP authentication module (lemur/auth/ldap.py) construc...
CVE-2026-44302HIGH7.5Snappier is a high performance C# implementation of the Snappy compression algorithm. Prior to 1.3.1, Snappier.SnappyStr...
CVE-2026-44301HIGH8.1Hugo is a static site generator. From 0.43 to before 0.161.0, when building a Hugo site that uses Node-based asset pipel...
CVE-2026-44296HIGH7.5Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a remote, unauthenticated denial of service (DoS) vul...
CVE-2026-44260HIGH8.1efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the readonly flag set on the <efw:elFinder> JSP tag is int...
CVE-2026-44241HIGH7.5Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applicat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now