2026 CVE Vulnerabilities

52,193 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-34403HIGH8.1Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui u...
CVE-2026-33626HIGH7.5LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Ser...
CVE-2026-33031HIGH8.1Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an adminis...
CVE-2026-29648HIGH8.8In OpenXiangShan NEMU, when Smstateen is enabled, clearing mstateen0.ENVCFG does not correctly restrict access to henvcf...
CVE-2026-29642HIGH7.8A local attacker who can execute privileged CSR operations (or can induce firmware to do so) performs carefully crafted ...
CVE-2026-6249HIGH8.8Vvveb CMS 1.0.8.2 contains a remote code execution vulnerability in its media upload handler that allows authenticated a...
CVE-2026-5478HIGH8.1The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and incl...
CVE-2026-32135HIGH7.5NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.11 have a remotely triggera...
CVE-2026-29645HIGH7.5NEMU (OpenXiangShan/NEMU) before v2025.12.r2 contains an improper instruction-validation flaw in its RISC-V Vector (RVV)...
CVE-2026-6248HIGH8.1The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. Th...
CVE-2026-39111HIGH7.5SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the ema...
CVE-2026-39110HIGH8.2SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the con...
CVE-2026-6662HIGH7.3A vulnerability was found in ericc-ch copilot-api up to 0.7.0. The impacted element is the function cors of the file src...
CVE-2026-41445HIGH8.8KissFFT before commit 8a8e66e contains an integer overflow vulnerability in the kiss_fftndr_alloc() function in kiss_fft...
CVE-2026-40488HIGH8.8Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun...
CVE-2026-30266HIGH7.8Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbit...
CVE-2026-26943HIGH7.2Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r...
CVE-2026-26942HIGH7.2Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used i...
CVE-2026-25524HIGH8.1Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun...
CVE-2026-24506HIGH7.2Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r...
CVE-2026-24505HIGH7.2Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain an improper input validation vulnerability. A high privi...
CVE-2026-24504HIGH7.2Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r...
CVE-2026-22761HIGH7.2Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A high privileged att...
CVE-2026-6066HIGH7.1ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automa...
CVE-2026-41245HIGH7.5Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFold...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now