2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-37337HIGH7.3SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_playlist....
CVE-2026-37336HIGH7.3SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_music.php...
CVE-2026-30656HIGH7.5A NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the...
CVE-2026-30459HIGH7.1An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the...
CVE-2026-5785HIGH8.1Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are ...
CVE-2026-31987HIGH7.5JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to up...
CVE-2026-3489HIGH7.5The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to SQL Injection vi...
CVE-2026-23772HIGH7.3Dell Storage Manager - Replay Manager for Microsoft Servers, version(s) 8.0, contain(s) an Improper Privilege Management...
CVE-2026-41035HIGH7.8In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiv...
CVE-2026-3876HIGH7.2The Prismatic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prismatic_encoded' pseudo-short...
CVE-2026-3861HIGH7.1LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web ...
CVE-2026-1620HIGH8.8The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and ...
CVE-2026-5050HIGH7.5The Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to Improper Verification of Cryptog...
CVE-2026-3614HIGH8.8The AcyMailing plugin for WordPress is vulnerable to privilege escalation in all versions From 9.11.0 up to, and includi...
CVE-2026-3599HIGH7.5The Riaxe Product Customizer plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter keys within...
CVE-2026-22618HIGH7.1A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was...
CVE-2026-22617HIGH7.4Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacke...
CVE-2026-22616HIGH7.5Eaton Intelligent Power Protector (IPP) software allows repeated authentication attempts against the web interface login...
CVE-2026-22615HIGH7.2Due to improper input validation in one of the Eaton Intelligent Power Protector (IPP) XML, it is possible for an attack...
CVE-2026-6351HIGH8.7MailGates/MailAudit developed by Openfind has a CRLF Injection vulnerability, allowing unauthenticated remote attackers ...
CVE-2026-41015HIGH7.4radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE...
CVE-2026-40960HIGH8.1Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as s...
CVE-2026-40503HIGH7.1OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat a...
CVE-2026-40502HIGH8.8OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with cha...
CVE-2026-5363HIGH8.8Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now