2026 CVE Vulnerabilities

55,393 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-10818HIGH8.1The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1...
CVE-2026-66374HIGH8.1Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) rece...
CVE-2026-66373HIGH7.5Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code executio...
CVE-2026-66339MEDIUM6.5A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches t...
CVE-2026-66338HIGH7.2A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes tha...
CVE-2026-66337MEDIUM6.5A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes ...
CVE-2026-61892HIGH8.8Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
CVE-2026-61886HIGH7.1Weintek cMT3092X HMI stores user account passwords in plaintext.
CVE-2026-60135HIGH7.1An attacker can modify data that should be restricted to read‑only access.
CVE-2026-60134HIGH8.8Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.
CVE-2026-16280CRITICAL9.8An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computa...
CVE-2026-61884CRITICAL9.8The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on...
CVE-2026-55985MEDIUM4.3The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on...
CVE-2026-66041HIGH7.8FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc fil...
CVE-2026-66040HIGH8.8FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and A...
CVE-2026-66039HIGH7.8FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decod...
CVE-2026-66038MEDIUM6.5FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video de...
CVE-2026-66037MEDIUM5.5FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF d...
CVE-2026-66036HIGH8.8FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter...
CVE-2026-62835HIGH7.5Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
CVE-2026-57531MEDIUM5.4Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allo...
CVE-2026-57530MEDIUM5.4Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milk...
CVE-2026-54342HIGH8.1In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensyste...
CVE-2026-48037MEDIUM6.3Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P...
CVE-2026-48036HIGH8.4Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now