2026 CVE Vulnerabilities

53,576 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-2579HIGH7.5The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to SQL Injection via th...
CVE-2026-4289HIGH7.3A security vulnerability has been detected in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This affects an ...
CVE-2026-4288HIGH7.3A weakness has been identified in Tiandy Easy7 Integrated Management Platform 7.17.0. The impacted element is an unknown...
CVE-2026-4287HIGH7.3A security flaw has been discovered in Tiandy Easy7 Integrated Management Platform 7.17.0. The affected element is an un...
CVE-2026-2454HIGH8.6Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported array le...
CVE-2026-29522HIGH8.7ZwickRoell Test Data Management versions prior to 3.0.8 contain a local file inclusion (LFI) vulnerability in the /serve...
CVE-2026-32264HIGH7.2Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-R...
CVE-2026-32263HIGH7.2Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.11, in src/controllers/EntryTyp...
CVE-2026-30881HIGH8.8Chamilo LMS is a learning management system. Version 1.11.34 and prior contains a SQL Injection vulnerability in the sta...
CVE-2026-30875HIGH8.8Chamilo LMS is a learning management system. Prior to version 1.11.36, an arbitrary file upload vulnerability in the H5P...
CVE-2026-32261HIGH8.5Webhooks for Craft CMS plugin adds the ability to manage “webhooks” in Craft CMS, which will send GET or POST requests w...
CVE-2026-4269HIGH7.5A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote a...
CVE-2026-4253HIGH7.2A security flaw has been discovered in Tenda AC8 16.03.50.11. This affects the function route_set_user_policy_rule of th...
CVE-2026-4224HIGH7.5When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply ...
CVE-2026-3644HIGH7.5The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()...
CVE-2026-28498HIGH7.5Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulne...
CVE-2026-23862HIGH7.8Dell ThinOS 10 versions prior to ThinOS 2602_10.0573, contain an Improper Neutralization of Special Elements used in a C...
CVE-2026-30405HIGH7.5An issue in GoBGP gobgpd v.4.2.0 allows a remote attacker to cause a denial of service via the NEXT_HOP path attribute
CVE-2026-4276HIGH7.5LibreChat RAG API, version 0.7.0, contains a log-injection vulnerability that allows attackers to forge log entries.
CVE-2026-25369HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexmls Flexmls® I...
CVE-2026-4255HIGH7.8A DLL search order hijacking vulnerability in Thermalright TR-VISION HOME on Windows (64-bit) allows a local attacker to...
CVE-2026-4240HIGH7.5A vulnerability was determined in Open5GS up to 2.7.6. The affected element is the function smf_gx_cca_cb/smf_gy_cca_cb/...
CVE-2026-4237HIGH7.3A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the ...
CVE-2026-4236HIGH7.3A security vulnerability has been detected in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function...
CVE-2026-4235HIGH7.3A weakness has been identified in itsourcecode Online Enrollment System 1.0. This issue affects some unknown processing ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now