2026 CVE Vulnerabilities

43,277 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-18655HIGH7.1Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs....
CVE-2026-18641HIGH7.3A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by...
CVE-2026-59913HIGH7.8Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Criti...
CVE-2026-59912HIGH7.8Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnera...
CVE-2026-61524HIGH8.6WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature th...
CVE-2026-61523HIGH8.6WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated...
CVE-2026-40717HIGH7.8Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnera...
CVE-2026-69152HIGH7.5The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3...
CVE-2026-67611HIGH8.6OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to ci...
CVE-2026-67610HIGH8.1OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoi...
CVE-2026-61372HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. Thi...
CVE-2026-41453HIGH8.8Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated use...
CVE-2026-39931HIGH8.6OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature t...
CVE-2026-18718HIGH7.1Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to exe...
CVE-2026-18607HIGH8.8A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN53...
CVE-2026-18606HIGH7.8A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown function...
CVE-2026-18605HIGH7A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown function in the library A...
CVE-2026-18568HIGH7.5XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when ev...
CVE-2026-67609HIGH8.5Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalatio...
CVE-2026-69097HIGH7.3GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitra...
CVE-2026-69096HIGH8.8OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after...
CVE-2026-69095HIGH8.7OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in ...
CVE-2026-69093HIGH7.1Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs pe...
CVE-2026-69091HIGH8.7Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only ...
CVE-2026-69089HIGH8.7Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $image...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now