2026 CVE Vulnerabilities

53,579 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-31922HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Fox LMS fo...
CVE-2026-31917HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp ...
CVE-2026-31899HIGH7.5CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to Kozea/CairoSVG has exponential denial of se...
CVE-2026-31886HIGH7.6Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, the dagRunId request field accepted by the...
CVE-2026-31884HIGH7.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, division by zero in MS-ADPCM and IMA-A...
CVE-2026-31882HIGH7.5Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, when Dagu is configured with HTTP Basic au...
CVE-2026-31814HIGH7.5Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. From 0.13.0 to before 0.13.9, a special...
CVE-2026-30914HIGH8.1SFTPGo is an open source, event-driven file transfer solution. In SFTPGo versions prior to 2.7.1, a path normalization d...
CVE-2026-30853HIGH8.2calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to 9.5.0, a p...
CVE-2026-2890HIGH7.5The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and includi...
CVE-2026-29775HIGH8.2FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap out-of-bounds read/...
CVE-2026-29774HIGH8.2FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap buffer overflow occ...
CVE-2026-29079HIGH7.5Lexbor is a web browser engine library. Prior to 2.7.0, a type‑confusion vulnerability exists in Lexbor’s HTML fragment ...
CVE-2026-29078HIGH7.5Lexbor is a web browser engine library. Prior to 2.7.0, the ISO‑2022‑JP encoder in Lexbor fails to reset the temporary s...
CVE-2026-25819HIGH7.5HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23...
CVE-2026-25817HIGH8.8HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23...
CVE-2026-25076HIGH8.5Anchore Enterprise versions before 5.25.1 contain an SQL injection vulnerability in the GraphQL Reports API. An authenti...
CVE-2026-22199HIGH8.7Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi en...
CVE-2026-22193HIGH7.5wpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions() function where string parame...
CVE-2026-22182HIGH8.7wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigge...
CVE-2026-0957HIGH8.5There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted file in Digilent DASYL...
CVE-2026-0956HIGH8.5There is a memory corruption vulnerability due to an out-of-bounds read when loading a corrupted file in Digilent DASYLa...
CVE-2026-0955HIGH8.5There is a memory corruption vulnerability due to an out-of-bounds read when loading a corrupted file in Digilent DASYLa...
CVE-2026-0954HIGH8.5There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted DSB file in Digilent D...
CVE-2026-2229HIGH7.5ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_m...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now