2026 CVE Vulnerabilities

51,063 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-8159HIGH7.5multiparty@4.2.3 and lower versions are vulnerable to denial of service via regular expression backtracking in the Conte...
CVE-2026-6001HIGH8.8Authorization bypass through User-Controlled key vulnerability in ABIS Technology Ltd. Co. BAPSİS allows Exploitation of...
CVE-2026-5029HIGH8.7A remote code execution vulnerability exists in Code Runner MCP Server when run with the --transport http option, which ...
CVE-2026-44412HIGH7.8A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5). The affected applications con...
CVE-2026-44411HIGH7.8A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5). The affected application is v...
CVE-2026-33893HIGH8.7A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2...
CVE-2026-27662HIGH7.7Affected devices do not properly restrict access to the web browser via the Control Panel when no corresponding security...
CVE-2026-25789HIGH7.2Affected devices do not properly validate and sanitize filenames on the Firmware Update page. This could allow a remote ...
CVE-2026-22925HIGH8.7A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application is susceptible to...
CVE-2026-6690HIGH7.2The LifePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'n' parameter of the lp_update_m...
CVE-2026-39432HIGH8.2Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Securi...
CVE-2026-2993HIGH7.5The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection in versions up to, and ...
CVE-2026-35227HIGH8.2An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a...
CVE-2026-1185HIGH8.8A configuration file on the local file system had improper input validation which could allow code execution and potenti...
CVE-2026-0804HIGH7.3An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to pote...
CVE-2026-0802HIGH7.3An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead ...
CVE-2026-0541HIGH7.3ACAP applications can gain elevated privileges due to improper input validation during the installation process, potenti...
CVE-2026-7287HIGH7.5** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formU...
CVE-2026-7256HIGH8.8** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware versio...
CVE-2026-45430HIGH7.1The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a random state parameter to protect the au...
CVE-2026-34259HIGH8.2Due to an OS Command Execution vulnerability in SAP Forecasting & Replenishment, an authenticated attacker with administ...
CVE-2026-45393HIGH8.5A vulnerability chain in Cribl Edge for Windows before 4.17.1 allows a local authenticated user to escalate privileges t...
CVE-2026-45392HIGH8.7DOM-based cross-site scripting (XSS) in Cribl Stream before 4.17.1 allows a remote attacker to execute arbitrary JavaScr...
CVE-2026-45391HIGH8.5A command injection vulnerability in Cribl Edge for Linux versions 3.2.0 through 4.17.0 allows a local unprivileged user...
CVE-2026-8346HIGH8.8A vulnerability was detected in D-Link DIR-816 1.10CNB05_R1B011D88210. This affects the function portForward. Performing...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now