2026 CVE Vulnerabilities

43,564 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-18412CRITICAL9.1OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 exten...
CVE-2026-72751MEDIUM5.1CTI-Transmute is affected by a stored cross-site scripting (XSS) vulnerability in the conversion graph used to visualise...
CVE-2026-71959MEDIUM5.8Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /c...
CVE-2026-63106CRITICAL9.8ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the...
CVE-2026-63105MEDIUM5.4ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated custome...
CVE-2026-59112MEDIUM4.4Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability ...
CVE-2026-18503LOW2.4Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume si...
CVE-2026-18478MEDIUM5.1Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrar...
CVE-2026-16742MEDIUM6.7systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed...
CVE-2026-15060MEDIUM4.7When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running o...
CVE-2026-15059MEDIUM5.5Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traver...
CVE-2026-72692HIGH7.5A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote att...
CVE-2026-72691HIGH7.5An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote at...
CVE-2026-72690HIGH7.1An improper authorization vulnerability in Attendize through commit 9289acb allows an authenticated remote attacker to i...
CVE-2026-72689HIGH7.5A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticate...
CVE-2026-72688HIGH7.5A missing authentication vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote at...
CVE-2026-6374HIGH7.3Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601 allows Read Sensitive Constants Within an Executab...
CVE-2026-6373MEDIUM6.5Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allow...
CVE-2026-68428In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Fix use-after-free on vendor module r...
CVE-2026-68427In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Fix use-after-free in host1x_bo_clear_...
CVE-2026-68426In the Linux kernel, the following vulnerability has been resolved: xfrm: fix stale skb->prev after async crypto steals...
CVE-2026-68425In the Linux kernel, the following vulnerability has been resolved: IB/mad: Drop unmatched RMPP responses before reasse...
CVE-2026-68424In the Linux kernel, the following vulnerability has been resolved: mtd: virt_concat: fix use-after-free in mtd_virt_co...
CVE-2026-68423In the Linux kernel, the following vulnerability has been resolved: mtd: virt_concat: fix use-after-free in mtd_virt_co...
CVE-2026-68422In the Linux kernel, the following vulnerability has been resolved: btrfs: fix root leak if its reloc root is unexpecte...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now