2026 CVE Vulnerabilities

53,074 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-4344HIGH7.1A maliciously crafted HTML payload in a component name, when displayed during the delete confirmation dialog and clicked...
CVE-2026-2450HIGH7.4.NET misconfiguration: use of impersonation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows...
CVE-2026-33892HIGH7.1A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1.7.6 < V1.15.17), Industrial...
CVE-2026-31923HIGH7.5Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in o...
CVE-2026-27668HIGH8.8A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8). U...
CVE-2026-25654HIGH8.8A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate u...
CVE-2026-24032HIGH7.3A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC). The affected application contains a...
CVE-2026-3017HIGH7.2The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to P...
CVE-2026-40287HIGH8.4PraisonAI is a multi-agent teams system. Versions 4.5.138 and below are vulnerable to arbitrary code execution through a...
CVE-2026-6227HIGH7.2The BackWPup plugin for WordPress is vulnerable to Local File Inclusion via the `block_name` parameter of the `/wp-json/...
CVE-2026-4388HIGH7.2The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box...
CVE-2026-4352HIGH7.5The JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endp...
CVE-2026-39421HIGH7.4MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a sandbox escape vulnerability in ...
CVE-2026-39420HIGH7.4MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, an incomplete sandbox protection mecha...
CVE-2026-39418HIGH7.4MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, sandbox network protection can be bypa...
CVE-2026-34256HIGH7.1Due to a missing authorization check in SAP ERP and SAP S/4HANA (Private Cloud and On-Premise), an authenticated attacke...
CVE-2026-40164HIGH7.5jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a ...
CVE-2026-5086HIGH7.5Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks. For example, if Crypt::SecretBuff...
CVE-2026-6224HIGH7.3A security flaw has been discovered in nocobase plugin-workflow-javascript up to 2.0.23. This issue affects the function...
CVE-2026-4786HIGH7.1Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain b...
CVE-2026-33908HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7....
CVE-2026-33905HIGH7.1ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7....
CVE-2026-22566HIGH7.5An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to obtain U...
CVE-2026-22565HIGH7.5An Improper Input Validation vulnerability could allow a malicious actor with access to the UniFi Play network to cause ...
CVE-2026-33901HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now