2026 CVE Vulnerabilities

53,457 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-32622HIGH8.8SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a S...
CVE-2026-26139HIGH8.6Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a net...
CVE-2026-26136HIGH7.5Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut...
CVE-2026-26120HIGH7.5Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network...
CVE-2026-23659HIGH7.5Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disc...
CVE-2026-25667HIGH7.5ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause ex...
CVE-2026-2646HIGH8.1A heap-buffer-overflow vulnerability exists in wolfSSL's wolfSSL_d2i_SSL_SESSION() function. When deserializing session ...
CVE-2026-2645HIGH7.5In wolfSSL 5.8.2 and earlier, a logic flaw existed in the TLS 1.2 server state machine implementation. The server could ...
CVE-2026-30403HIGH7.5There is an arbitrary file read vulnerability in the test connection function of backend database management in wgcloud ...
CVE-2026-0819HIGH7.1A stack buffer overflow vulnerability exists in wolfSSL's PKCS7 SignedData encoding functionality. In wc_PKCS7_BuildSign...
CVE-2026-3029HIGH7.5A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF ver...
CVE-2026-30404HIGH7.5The backend database management connection test feature in wgcloud v3.6.3 has a server-side request forgery (SSRF) vulne...
CVE-2026-4424HIGH7.5A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic du...
CVE-2026-30711HIGH8.8Devome GRR v4.5.0 was discovered to contain multiple authenticated SQL injection vulnerabilities in the include/session....
CVE-2026-27043HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGoods Photography allows Path Traversal.This issue...
CVE-2026-22558HIGH7.7An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with aut...
CVE-2026-3658HIGH7.5The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL...
CVE-2026-3511HIGH8.6Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allow...
CVE-2026-27070HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPEverest Everest ...
CVE-2026-27068HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Howard Websit...
CVE-2026-25445HIGH8.8Deserialization of Untrusted Data vulnerability in Membership Software WishList Member X allows Object Injection.This is...
CVE-2026-25443HIGH7.5Missing Authorization vulnerability in Dotstore Fraud Prevention For Woocommerce woo-blocker-lite-prevent-fake-orders-an...
CVE-2026-25442HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QantumThemes Kenth...
CVE-2026-25438HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Gutenber...
CVE-2026-25471HIGH8.1Authentication Bypass Using an Alternate Path or Channel vulnerability in Themepaste Admin Safety Guard admin-safety-gua...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now