2026 CVE Vulnerabilities

53,351 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-24068HIGH8.8The VSL privileged helper does utilize NSXPC for IPC. The implementation of the "shouldAcceptNewConnection" function, wh...
CVE-2026-23397HIGH7.1In the Linux kernel, the following vulnerability has been resolved: nfnetlink_osf: validate individual option lengths i...
CVE-2026-4862HIGH8.8A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This issue affects the functio...
CVE-2026-4861HIGH8.8A weakness has been identified in Wavlink WL-NU516U1 260227. This vulnerability affects the function ftext of the file /...
CVE-2026-4860HIGH7.3A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. This affects the function GenericFastJsonR...
CVE-2026-4747HIGH8.8Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet. This routine copies a por...
CVE-2026-4652HIGH7.5On a system exposing an NVMe/TCP target, a remote client can trigger a kernel panic by sending a CONNECT command for an ...
CVE-2026-4247HIGH7.5When a challenge ACK is to be sent tcp_respond() constructs and sends the challenge ACK and consumes the mbuf that is pa...
CVE-2026-32680HIGH8.5The installer of RATOC RAID Monitoring Manager for Windows allows to customize the installation folder. If the installat...
CVE-2026-28760HIGH8.4The installer of RATOC RAID Monitoring Manager for Windows searches the current directory to load certain DLLs. If a use...
CVE-2026-4844HIGH7.3A vulnerability was detected in code-projects Online Food Ordering System 1.0. This issue affects some unknown processin...
CVE-2026-4842HIGH7.3A security vulnerability has been detected in itsourcecode Online Enrollment System 1.0. This vulnerability affects unkn...
CVE-2026-4841HIGH7.3A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the fil...
CVE-2026-4840HIGH8.8A security flaw has been discovered in Netcore Power 15AX up to 3.0.0.6938. Affected by this issue is the function setTo...
CVE-2026-4329HIGH7.2The Blackhole for Bad Bots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent HTTP hea...
CVE-2026-33201HIGH7Digital Photo Frame GH-WDF10A provided by GREEN HOUSE CO., LTD. contains an active debug code vulnerability. If this vul...
CVE-2026-2931HIGH8.8The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and includ...
CVE-2026-4839HIGH7.3A vulnerability has been found in SourceCodester Food Ordering System 1.0. This affects an unknown function of the file ...
CVE-2026-4838HIGH7.3A flaw has been found in SourceCodester Malawi Online Market 1.0. The impacted element is an unknown function of the fil...
CVE-2026-3328HIGH7.2The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to PHP Object Injection via deserialization of the '...
CVE-2026-4484HIGH8.8The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6...
CVE-2026-33526HIGH7.5Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of...
CVE-2026-33287HIGH7.5LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, the `repla...
CVE-2026-33285HIGH7.5LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, LiquidJS's...
CVE-2026-33182HIGH7.5Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, when building...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now