2026 CVE Vulnerabilities

55,766 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-66139MEDIUM4.8OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.
CVE-2026-66138HIGH7.2In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code ...
CVE-2026-54422MEDIUM5.5In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, m...
CVE-2026-6454MEDIUM6.4The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and inclu...
CVE-2026-15420MEDIUM4.3The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory ...
CVE-2026-15100MEDIUM6.4The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnore...
CVE-2026-13464MEDIUM5.3The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Ob...
CVE-2026-12736HIGH8The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This ...
CVE-2026-11922MEDIUM6.5A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST...
CVE-2026-11354MEDIUM5.3The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an...
CVE-2026-62825CRITICAL9.8Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-58275CRITICAL9.8Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56191CRITICAL10Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network...
CVE-2026-56167HIGH8.8Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network...
CVE-2026-56165CRITICAL9.8Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
CVE-2026-56160CRITICAL9.9Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a netwo...
CVE-2026-54120HIGH8.8Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
CVE-2026-50517CRITICAL9.9Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
CVE-2026-49159MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose ...
CVE-2026-35425HIGH7.2Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
CVE-2026-50044HIGH7.6Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an...
CVE-2026-44955MEDIUM6.9Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized contr...
CVE-2026-42933CRITICAL10Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow ...
CVE-2026-40430HIGH8.7Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cl...
CVE-2026-28698CRITICAL9.2Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized contr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now