2026 CVE Vulnerabilities

51,076 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-7818HIGH7.8Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager. The session manager performed unsafe...
CVE-2026-7817HIGH7.1Local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities in pgAdmin 4 LLM API configuration end...
CVE-2026-7816HIGH8.8OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export. User-supplied input was interpolat...
CVE-2026-7815HIGH8.8SQL injection vulnerability in pgAdmin 4 Maintenance Tool. Four user-supplied JSON fields (buffer_usage_limit, vacuum_p...
CVE-2026-42611HIGH8.9Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can ...
CVE-2026-42609HIGH8.1Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows ...
CVE-2026-34092HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne...
CVE-2026-34091HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue ...
CVE-2026-34090HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation CheckUser. This issue ...
CVE-2026-34089HIGH7.5Vulnerability in Wikimedia Foundation Scribunto. This issue affects Scribunto: from 1.45.0 before 1.45.2.
CVE-2026-34088HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue ...
CVE-2026-34087HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation OATHAuth. This issue a...
CVE-2026-31247HIGH7.5Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse...
CVE-2026-4802HIGH8A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the h...
CVE-2026-41951HIGH8.6Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS te...
CVE-2026-40636HIGH7.8Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded c...
CVE-2026-32658HIGH8.8Dell Automation Platform versions prior to 2.0.0.0, contains a missing authorization vulnerability. A low privileged att...
CVE-2026-43500HIGH7.8In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when page...
CVE-2026-6433HIGH7.3The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL quer...
CVE-2026-8273HIGH7.2A weakness has been identified in D-Link DNS-320 2.06B01. This impacts the function cgi_set_host/cgi_set_ntp/cgi_fan_con...
CVE-2026-8272HIGH7.2A security flaw has been discovered in D-Link DNS-320 2.06B01. This affects the function delete/rename/copy/move/chmod/c...
CVE-2026-8271HIGH7.2A vulnerability was identified in D-Link DNS-320 2.06B01. The impacted element is the function cgi_speed/cgi_dhcpd_lease...
CVE-2026-8265HIGH7.2A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file...
CVE-2026-8264HIGH8.8A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan o...
CVE-2026-8260HIGH8.8A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now