2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-57511MEDIUM6.3SuperPlane before 0.30.0 contains an SMTP header injection vulnerability that allows unauthenticated attackers to inject...
CVE-2026-57510HIGH8.8SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers t...
CVE-2026-55555HIGH7.5Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existence Oracle attack thr...
CVE-2026-55554HIGH7.5Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot bo...
CVE-2026-48060HIGH8.1Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which...
CVE-2026-3158MEDIUM4.3IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM ...
CVE-2026-3157MEDIUM4.3IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM ...
CVE-2026-1918MEDIUM4.9IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM ...
CVE-2026-16347HIGH8.8MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessi...
CVE-2026-16192MEDIUM6.5IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability wh...
CVE-2026-16184CRITICAL9.8IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafte...
CVE-2026-16107MEDIUM5.9IBM TS4500 CLI tool Versions:  0.1.31 through 1.12.0.0 does not validate or improperly validates TLS certificate validat...
CVE-2026-11391MEDIUM6.3Tanium addressed a SQL injection vulnerability in Patch.
CVE-2026-7769HIGH8.1IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM ...
CVE-2026-7362MEDIUM6.5IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.1...
CVE-2026-66745HIGH7.5Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability t...
CVE-2026-5114MEDIUM4.9The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and ...
CVE-2026-59932HIGH7.5PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 t...
CVE-2026-50738MEDIUM5.3A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced aft...
CVE-2026-50737HIGH7.5When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's...
CVE-2026-50736HIGH7.5The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscrib...
CVE-2026-50735MEDIUM6.8pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol me...
CVE-2026-4932MEDIUM4.2IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physica...
CVE-2026-4912MEDIUM4.1The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio...
CVE-2026-49258HIGH8.8Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now