2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-5718HIGH8.1The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in...
CVE-2026-5710HIGH7.5The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading t...
CVE-2026-40320HIGH7.8Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the ConformityCheck class rende...
CVE-2026-3464HIGH8.8The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file pat...
CVE-2026-21733HIGH7.3Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to re...
CVE-2026-6490HIGH7.3A weakness has been identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. Impacted is an unknown f...
CVE-2026-40459HIGH8.8PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP synt...
CVE-2026-31317HIGH7.5Craftql v1.3.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitr...
CVE-2026-6507HIGH7.5A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially...
CVE-2026-6483HIGH7.3A vulnerability was found in Wavlink WL-WN530H4 20220721. This vulnerability affects the function strcat/snprintf of the...
CVE-2026-23776HIGH8.8Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,...
CVE-2026-23778HIGH7.2Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,...
CVE-2026-40002HIGH8.8Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operatio...
CVE-2026-33392HIGH7.2In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass
CVE-2026-23853HIGH8.4Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,...
CVE-2026-4659HIGH7.5The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV...
CVE-2026-6482HIGH7.8The Rapid7 Insight Agent (versions > 4.1.0.2) is vulnerable to a local privilege escalation attack that allows users to ...
CVE-2026-6421HIGH7A vulnerability has been found in Mobatek MobaXterm Home Edition up to 26.1. This affects an unknown part in the library...
CVE-2026-21719HIGH8.6An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative p...
CVE-2026-5807HIGH7.5Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel...
CVE-2026-5052HIGH8.6Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This ...
CVE-2026-4525HIGH8.8If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used t...
CVE-2026-3605HIGH8.1An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they w...
CVE-2026-5231HIGH7.2The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in al...
CVE-2026-40262HIGH8.7Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset delivery handler serves upl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now