2026 CVE Vulnerabilities

52,737 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-50735MEDIUM6.8pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol me...
CVE-2026-4932MEDIUM4.2IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physica...
CVE-2026-4912MEDIUM4.1The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio...
CVE-2026-49258HIGH8.8Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*...
CVE-2026-48396HIGH8.6Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the cont...
CVE-2026-48395HIGH8.6Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the contex...
CVE-2026-48394HIGH7.8Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context ...
CVE-2026-48393HIGH7.8Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context ...
CVE-2026-48392HIGH7.8Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context ...
CVE-2026-48391HIGH8.2Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the contex...
CVE-2026-48390HIGH8.2Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker co...
CVE-2026-48374HIGH7.8Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability th...
CVE-2026-48058MEDIUM4.6nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, intern...
CVE-2026-47768MEDIUM5.5nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-...
CVE-2026-47726HIGH7.1nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, intern...
CVE-2026-47725MEDIUM6.9nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every ...
CVE-2026-18107HIGH7.8A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process insid...
CVE-2026-16771HIGH8.8In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on ...
CVE-2026-16498CRITICAL10The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-H...
CVE-2026-16496HIGH8.9The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful t...
CVE-2026-15992HIGH8.8The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3....
CVE-2026-15304MEDIUM6.5The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions ...
CVE-2026-14869HIGH8.6The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTT...
CVE-2026-59933HIGH7.5PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 t...
CVE-2026-59931HIGH7.7PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now