2026 CVE Vulnerabilities

43,284 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-17347HIGH8.8The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that ...
CVE-2026-17346HIGH8.8The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatin...
CVE-2026-10686HIGH7.5Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop limit. Both routing ...
CVE-2026-18446HIGH7.5fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a refer...
CVE-2026-10685HIGH7.6The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked...
CVE-2026-18358HIGH7.5A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mo...
CVE-2026-46593HIGH8.6A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input...
CVE-2026-62391HIGH8.1The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend...
CVE-2026-16843HIGH7.2Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validatio...
CVE-2026-15722HIGH7.5A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function ...
CVE-2026-11770HIGH7.5A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the Cle...
CVE-2026-10079HIGH8.5A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, AC...
CVE-2026-65313HIGH8.1A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-c...
CVE-2026-65310HIGH7.5ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configu...
CVE-2026-65309HIGH7.5ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible form...
CVE-2026-18215HIGH8.1Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization...
CVE-2026-18214HIGH8.1Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Wor...
CVE-2026-16236HIGH8.8The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5...
CVE-2026-15258HIGH8.1The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-fe...
CVE-2026-15048HIGH7.5The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowin...
CVE-2026-14930HIGH7.5The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front...
CVE-2026-14830HIGH7.5The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually...
CVE-2026-14333HIGH7.5The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a p...
CVE-2026-14319HIGH7.5The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurri...
CVE-2026-13609HIGH8.8The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value af...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now