2026 CVE Vulnerabilities

52,167 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-35570HIGH8.4OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Versions prior to ...
CVE-2026-6729HIGH7.6HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated...
CVE-2026-29643HIGH7.1XiangShan (Open-source high-performance RISC-V processor) commit edb1dfaf7d290ae99724594507dc46c2c2125384 (2024-11-28) c...
CVE-2026-5928HIGH7.5Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between ...
CVE-2026-34403HIGH8.1Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui u...
CVE-2026-33626HIGH7.5LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Ser...
CVE-2026-33031HIGH8.1Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an adminis...
CVE-2026-29648HIGH8.8In OpenXiangShan NEMU, when Smstateen is enabled, clearing mstateen0.ENVCFG does not correctly restrict access to henvcf...
CVE-2026-29642HIGH7.8A local attacker who can execute privileged CSR operations (or can induce firmware to do so) performs carefully crafted ...
CVE-2026-6249HIGH8.8Vvveb CMS 1.0.8.2 contains a remote code execution vulnerability in its media upload handler that allows authenticated a...
CVE-2026-5478HIGH8.1The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and incl...
CVE-2026-32135HIGH7.5NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.11 have a remotely triggera...
CVE-2026-29645HIGH7.5NEMU (OpenXiangShan/NEMU) before v2025.12.r2 contains an improper instruction-validation flaw in its RISC-V Vector (RVV)...
CVE-2026-6248HIGH8.1The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. Th...
CVE-2026-39111HIGH7.5SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the ema...
CVE-2026-39110HIGH8.2SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the con...
CVE-2026-6662HIGH7.3A vulnerability was found in ericc-ch copilot-api up to 0.7.0. The impacted element is the function cors of the file src...
CVE-2026-41445HIGH8.8KissFFT before commit 8a8e66e contains an integer overflow vulnerability in the kiss_fftndr_alloc() function in kiss_fft...
CVE-2026-40488HIGH8.8Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun...
CVE-2026-30266HIGH7.8Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbit...
CVE-2026-26943HIGH7.2Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r...
CVE-2026-26942HIGH7.2Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used i...
CVE-2026-25524HIGH8.1Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun...
CVE-2026-24506HIGH7.2Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r...
CVE-2026-24505HIGH7.2Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain an improper input validation vulnerability. A high privi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now