2026 CVE Vulnerabilities

51,208 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-43074HIGH7.8In the Linux kernel, the following vulnerability has been resolved: eventpoll: defer struct eventpoll free to RCU grace...
CVE-2026-1719HIGH7.5The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2...
CVE-2026-7841HIGH8.8A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user...
CVE-2026-7332HIGH7.2The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2026-23928HIGH7.3The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when H...
CVE-2026-23926HIGH7.3An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by...
CVE-2026-7573HIGH7.7An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 a...
CVE-2026-40110HIGH7.3Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation...
CVE-2026-40075HIGH7.5OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8...
CVE-2026-40068HIGH8.8In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir f...
CVE-2026-39852HIGH8.2Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3...
CVE-2026-39849HIGH8.8Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1,...
CVE-2026-39383HIGH7.2Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access c...
CVE-2026-7857HIGH7.3A vulnerability has been found in D-Link DI-8100 16.07.26A1. This vulnerability affects the function sprintf of the file...
CVE-2026-7856HIGH7.3A flaw has been found in D-Link DI-8100 16.07.26A1. This affects an unknown part of the file /url_member.asp of the comp...
CVE-2026-44331HIGH8.1In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap...
CVE-2026-40280HIGH7.5Gotenberg is an API-based document conversion tool. In versions 8.30.1 and earlier, the default private-IP deny-lists fo...
CVE-2026-35397HIGH8.8Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerabili...
CVE-2026-34596HIGH7Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a Time-of...
CVE-2026-34464HIGH8.8Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipe...
CVE-2026-34462HIGH7.8Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several P...
CVE-2026-34461HIGH7.8Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieI...
CVE-2026-34459HIGH8.8Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieS...
CVE-2026-34458HIGH8.8Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI in...
CVE-2026-33975HIGH8.3Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and earlier, the SSRF protection in twenty-...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now