2026 CVE Vulnerabilities

64,785 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-92916HIGH7.5Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 2.0.0 through 2.0.21, when the debugger is enabled (system.d...
CVE-2026-92915HIGH7.3WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/use...
CVE-2026-92914HIGH8.1AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares ...
CVE-2026-92913HIGH7.4AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number genera...
CVE-2026-81480HIGH7.2Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability. ...
CVE-2026-81478HIGH8.1Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnera...
CVE-2026-81477HIGH7.2Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A...
CVE-2026-81476HIGH8.1Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Element...
CVE-2026-81475HIGH8.1Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Functio...
CVE-2026-81440HIGH7.3Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability...
CVE-2026-92903HIGH8.2Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-controlled values to be int...
CVE-2026-81474HIGH7.8Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A...
CVE-2026-66269HIGH7.3Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Selec...
CVE-2026-78428HIGH8For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving anoth...
CVE-2026-78425HIGH7.6Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticke...
CVE-2026-50610HIGH7.4A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense d...
CVE-2026-50609HIGH7.4A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. ...
CVE-2026-86320HIGH7.8A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. ...
CVE-2026-50605HIGH7.4A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. Insu...
CVE-2026-87963HIGH8.6The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before u...
CVE-2026-86801HIGH8.8The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress an...
CVE-2026-91014HIGH7.1The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its...
CVE-2026-88904HIGH8.8The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the...
CVE-2026-88792HIGH8.8The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding o...
CVE-2026-87786HIGH8.8The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputt...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now