2026 CVE Vulnerabilities
43,284 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50160 | CRITICAL | 10 | 0.6% | Jul 1, 2026 | Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and e... |
| CVE-2026-58521 | CRITICAL | 9.8 | 0.3% | Jul 1, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foun... |
| CVE-2026-58453 | CRITICAL | 9.8 | 1.7% | Jul 1, 2026 | JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that... |
| CVE-2026-34117 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in text_to_subtitles.php (line 19) ... |
| CVE-2026-34116 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe.php (line 15) without... |
| CVE-2026-34115 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe_amazon.php (line 15) ... |
| CVE-2026-34114 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate_text.php (line 18) wit... |
| CVE-2026-34113 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech_text.php (line 18) withou... |
| CVE-2026-34112 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac.php (line 18) without ... |
| CVE-2026-34111 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac_text.php (line 18) wit... |
| CVE-2026-34110 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (line 14) with... |
| CVE-2026-34109 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech.php (line 18) without san... |
| CVE-2026-34108 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanit... |
| CVE-2026-34107 | CRITICAL | 9.8 | 0.7% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14) without ... |
| CVE-2026-34106 | CRITICAL | 9.8 | 0.7% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without ... |
| CVE-2026-34105 | CRITICAL | 9.8 | 0.4% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line ... |
| CVE-2026-34104 | CRITICAL | 9.8 | 0.4% | Jul 1, 2026 | Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (line 124)... |
| CVE-2026-34103 | CRITICAL | 9.8 | 0.4% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): ... |
| CVE-2026-34102 | CRITICAL | 9.8 | 0.4% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16... |
| CVE-2026-34101 | CRITICAL | 9.8 | 0.4% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): ... |
| CVE-2026-34100 | CRITICAL | 9.8 | 0.4% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELE... |
| CVE-2026-34099 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): S... |
| CVE-2026-58127 | CRITICAL | 9.8 | 0.8% | Jul 1, 2026 | PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registere... |
| CVE-2026-58126 | CRITICAL | 9.8 | 0.8% | Jul 1, 2026 | PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to... |
| CVE-2026-58025 | CRITICAL | 9.8 | 0.3% | Jul 1, 2026 | Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated wi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now