2026 CVE Vulnerabilities

53,386 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-22496HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-22495HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-22494HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-22493HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-22491HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphocus My auction...
CVE-2026-22480HIGH7.2Deserialization of Untrusted Data vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows ...
CVE-2026-22448HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in flexcubed PitchPrint pit...
CVE-2026-20719HIGH7.5Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to prevent rendering ...
CVE-2026-1724HIGH7.5GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.1...
CVE-2026-20125HIGH7.7A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an aut...
CVE-2026-20086HIGH8.6A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) packets of Cisco IOS XE...
CVE-2026-20084HIGH8.6A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to...
CVE-2026-20012HIGH8.6A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cis...
CVE-2026-20004HIGH7.4A vulnerability in the TLS library of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust...
CVE-2026-4815HIGH8.8A SQL Injection vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to retrieve,...
CVE-2026-3104HIGH7.5A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This is...
CVE-2026-28529HIGH7.8cryptodev-linux version 1.14 and prior contain a page reference handling flaw in the get_userbuf function of the /dev/cr...
CVE-2026-1519HIGH7.5If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume e...
CVE-2026-4761HIGH7.5When a certificate and its private key are installed in the Windows machine certificate store using Network and Security...
CVE-2026-4760HIGH7.7From Panorama Web HMI, an attacker can gain read access to certain Web HMI server files, if he knows their paths and if ...
CVE-2026-31788HIGH8.2In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: restrict usage in unprivileged domU T...
CVE-2026-23395HIGH8.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix accepting multiple L2CAP_ECRE...
CVE-2026-23393HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bridge: cfm: Fix race condition in peer_mep deletio...
CVE-2026-23392HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: release flowtable after rcu g...
CVE-2026-23391HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_CT: drop pending enqueued packets on ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now