2026 CVE Vulnerabilities

53,398 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-3533HIGH8.8The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_pop...
CVE-2026-33283HIGH7.5Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing malformed UL NAS Tra...
CVE-2026-33282HIGH7.5Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing a malformed NGAP Loc...
CVE-2026-33281HIGH7.5Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing NGAP messages with i...
CVE-2026-33250HIGH7.5Freeciv21 is a free open source, turn-based, empire-building strategy game. Versions prior to 3.1.1 crash with a stack o...
CVE-2026-33242HIGH7.5Salvo is a Rust web framework. Versions 0.39.0 through 0.89.2 have a Path Traversal and Access Control Bypass vulnerabil...
CVE-2026-33241HIGH7.5Salvo is a Rust web framework. Prior to version 0.89.3, Salvo's form data parsing implementations (`form_data()` method ...
CVE-2026-33176HIGH7.5Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to v...
CVE-2026-33174HIGH7.5Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a...
CVE-2026-4306HIGH7.5The WP Job Portal plugin for WordPress is vulnerable to SQL Injection via the 'radius' parameter in all versions up to, ...
CVE-2026-33046HIGH8.8Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In vers...
CVE-2026-4612HIGH7.3A vulnerability has been found in itsourcecode Free Hotel Reservation System 1.0. This affects an unknown part of the fi...
CVE-2026-4611HIGH8.8A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the fu...
CVE-2026-33634HIGH8.8Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy...
CVE-2026-32300HIGH8.1Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the...
CVE-2026-32299HIGH7.5Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the...
CVE-2026-32277HIGH8.7Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cro...
CVE-2026-32276HIGH8.8Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the...
CVE-2026-1940HIGH7.5An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added...
CVE-2026-4368HIGH7.7Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN,...
CVE-2026-23882HIGH7.2Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the MCP (Model Context Protocol) server creati...
CVE-2026-23482HIGH7.5Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the file server endpoint does not perform perm...
CVE-2026-23480HIGH8.8Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is a privilege escalation vulnerability....
CVE-2026-33719HIGH8.6WWBN AVideo is an open source video platform. In versions up to and including 26.0, the CDN plugin endpoints `plugin/CDN...
CVE-2026-33717HIGH8.8WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `downloadVideoFromDownloadURL()`...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now