2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-30615HIGH8A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim...
CVE-2026-30461HIGH8.3Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via ...
CVE-2026-20205HIGH7.2In Splunk MCP Server app versions below 1.0.3 , a user who holds a role with access to the Splunk `_internal` index or p...
CVE-2026-20204HIGH7.1In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26...
CVE-2026-4682HIGH8.7Certain HP DeskJet All in One devices may be vulnerable to remote code execution caused by a buffer overflow when specia...
CVE-2026-4667HIGH7.3HP System Optimizer might potentially be vulnerable to escalation of privilege. HP is releasing an update to mitigate th...
CVE-2026-30364HIGH7.5CentSDR commit e40795 was discovered to contain a stack overflow in the "Thread1" function.
CVE-2026-4145HIGH7.8During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow...
CVE-2026-4134HIGH7.3During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during ins...
CVE-2026-0827HIGH7.1During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareS...
CVE-2026-40784HIGH8.1Authorization Bypass Through User-Controlled Key vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows ...
CVE-2026-40764HIGH8.1Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Cross Site Re...
CVE-2026-40745HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bdthemes Element P...
CVE-2026-40744HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beaver Builder Bea...
CVE-2026-33805HIGH8.6@fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client's Connection head...
CVE-2026-30778HIGH7.5The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL. Th...
CVE-2026-28741HIGH8.1Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to validate CSRF toke...
CVE-2026-5598HIGH8.9Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulne...
CVE-2026-5588HIGH7.5Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all...
CVE-2026-3505HIGH7.5Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the B...
CVE-2026-5694HIGH7.2The Quick Interest Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'loan-amount' and 'l...
CVE-2026-5617HIGH8.8The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3...
CVE-2026-3643HIGH7.2The Accessibly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in all versions up to,...
CVE-2026-5088HIGH7.5Apache::API::Password versions through 0.5.2 for Perl can generate insecure random values for salts. The _make_salt and...
CVE-2026-40719HIGH7.5Deadwood in MaraDNS 3.5.0036 allows attackers to exhaust connection slots via a zone whose authoritative nameserver addr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now