2026 CVE Vulnerabilities

51,117 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-41493HIGH7.5YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when u...
CVE-2026-41491HIGH8.1Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. From versions 1.3...
CVE-2026-39816HIGH8.8The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Requi...
CVE-2026-8077HIGH8.6Lack of proper authorization implementation in the CashDro 3 web administration panel, version 24.01.00.26. The backend ...
CVE-2026-25077HIGH8.8Account users are allowed by default to register templates to be downloaded directly to the primary storage for deployin...
CVE-2026-7330HIGH7.2The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ...
CVE-2026-5127HIGH8.8The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP...
CVE-2026-43284HIGH8.8In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb fra...
CVE-2026-8069HIGH7.8PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes ...
CVE-2026-4935HIGH8.6The OttoKit: All-in-One Automation Platform WordPress plugin before 1.1.23 does not properly sanitize user input before ...
CVE-2026-8148HIGH7.8NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM...
CVE-2026-8138HIGH8.8A vulnerability was found in Tenda CX12L 16.03.53.12. This issue affects the function formSetPPTPServer of the file /gof...
CVE-2026-8137HIGH8.8A vulnerability has been found in Totolink X5000R 9.1.0u.6369_B20230113. This vulnerability affects the function sub_458...
CVE-2026-42278HIGH8.8UltraDAG is a minimal DAG-BFT blockchain in Rust. Prior to commit fb6ef59, the UltraDAG StateEngine implementation of Sm...
CVE-2026-8133HIGH7.3A security vulnerability has been detected in zyx0814 FilePress up to 2.2.0. Affected by this vulnerability is an unknow...
CVE-2026-8132HIGH7.3A weakness has been identified in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /lo...
CVE-2026-8131HIGH7.3A security flaw has been discovered in SourceCodester SUP Online Shopping 1.0. This impacts an unknown function of the f...
CVE-2026-8130HIGH7.3A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. This affects an unknown function of the file /...
CVE-2026-8129HIGH7.3A vulnerability was determined in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of...
CVE-2026-43943HIGH7.8electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.9, a code...
CVE-2026-43940HIGH8.4electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.16, the r...
CVE-2026-42275HIGH8.7zrok is software for sharing web services, files, and network resources. Prior to version 2.0.2, the zrok WebDAV drive b...
CVE-2026-42274HIGH7.8Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall ...
CVE-2026-42273HIGH7.8Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall ...
CVE-2026-42272HIGH7.8Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now