2026 CVE Vulnerabilities

53,091 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-34256HIGH7.1Due to a missing authorization check in SAP ERP and SAP S/4HANA (Private Cloud and On-Premise), an authenticated attacke...
CVE-2026-40164HIGH7.5jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a ...
CVE-2026-5086HIGH7.5Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks. For example, if Crypt::SecretBuff...
CVE-2026-6224HIGH7.3A security flaw has been discovered in nocobase plugin-workflow-javascript up to 2.0.23. This issue affects the function...
CVE-2026-4786HIGH7.1Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain b...
CVE-2026-33908HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7....
CVE-2026-33905HIGH7.1ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7....
CVE-2026-22566HIGH7.5An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to obtain U...
CVE-2026-22565HIGH7.5An Improper Input Validation vulnerability could allow a malicious actor with access to the UniFi Play network to cause ...
CVE-2026-33901HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7....
CVE-2026-33900HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7....
CVE-2026-32272HIGH8.7Craft Commerce is an ecommerce platform for Craft CMS. In versions 5.0.0 through 5.5.4, an SQL injection vulnerability e...
CVE-2026-32271HIGH7.7Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, there i...
CVE-2026-32605HIGH7.5nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a...
CVE-2026-6200HIGH8.8A vulnerability was determined in Tenda F456 1.0.0.5. The affected element is the function formwebtypelibrary of the fil...
CVE-2026-6199HIGH8.8A vulnerability was found in Tenda F456 1.0.0.5. Impacted is the function fromqossetting of the file /goform/qossetting....
CVE-2026-6198HIGH8.8A vulnerability has been found in Tenda F456 1.0.0.5. This issue affects the function fromNatStaticSetting of the file /...
CVE-2026-6197HIGH8.8A flaw has been found in Tenda F456 1.0.0.5. This vulnerability affects the function formWrlsafeset of the file /goform/...
CVE-2026-40043HIGH7.1Pachno 1.0.6 contains an authentication bypass vulnerability in the runSwitchUser() action that allows authenticated low...
CVE-2026-40040HIGH8.8Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary file...
CVE-2026-40039HIGH7.1Pachno 1.0.6 contains an open redirection vulnerability that allows attackers to redirect users to arbitrary external we...
CVE-2026-40038HIGH7.2Pachno 1.0.6 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and sc...
CVE-2026-29955HIGH8.8The `/registercrd` endpoint in KubePlus 4.14 in the kubeconfiggenerator component is vulnerable to command injection. Th...
CVE-2026-6196HIGH8.8A vulnerability was detected in Tenda F456 1.0.0.5. This affects the function fromexeCommand of the file /goform/exeComm...
CVE-2026-6194HIGH8.8A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_41...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now