2026 CVE Vulnerabilities

52,659 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-5588HIGH7.5Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all...
CVE-2026-3505HIGH7.5Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the B...
CVE-2026-5694HIGH7.2The Quick Interest Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'loan-amount' and 'l...
CVE-2026-5617HIGH8.8The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3...
CVE-2026-3643HIGH7.2The Accessibly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in all versions up to,...
CVE-2026-5088HIGH7.5Apache::API::Password versions through 0.5.2 for Perl can generate insecure random values for salts. The _make_salt and...
CVE-2026-40719HIGH7.5Deadwood in MaraDNS 3.5.0036 allows attackers to exhaust connection slots via a zone whose authoritative nameserver addr...
CVE-2026-5397HIGH7.8It has been identified that a vulnerability (CWE-427) exists in the UPS (Uninterruptible Power Supply) management applic...
CVE-2026-6328HIGH8.3Improper input validation, Improper verification of cryptographic signature vulnerability in XQUIC Project XQUIC xquic o...
CVE-2026-40499HIGH7.8radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function tha...
CVE-2026-40104HIGH8.2XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 1.8-rc...
CVE-2026-40090HIGH7.1Zarf is an Airgap Native Packager Manager for Kubernetes. Versions 0.23.0 through 0.74.1 contain an arbitrary file write...
CVE-2026-39971HIGH7.2Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the email sending functionality in include/...
CVE-2026-39884HIGH8.1mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Versions 3.4.0 and prior con...
CVE-2026-33806HIGH7.5Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypasse...
CVE-2026-2834HIGH7.2The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2026-40688HIGH7.2An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 th...
CVE-2026-39387HIGH7.2BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. V...
CVE-2026-35032HIGH8.1Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the Live...
CVE-2026-35031HIGH8.8Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subt...
CVE-2026-33414HIGH7.8Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerab...
CVE-2026-33023HIGH7.8libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. In versions 1.8.7 and prior, when built w...
CVE-2026-33021HIGH7.3libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a use-af...
CVE-2026-27298HIGH7.8Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confus...
CVE-2026-27297HIGH7.8Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability tha...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now