2026 CVE Vulnerabilities

53,639 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-23660HIGH7.8Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally...
CVE-2026-23654HIGH8.8Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to...
CVE-2026-23239HIGH7.8In the Linux kernel, the following vulnerability has been resolved: espintcp: Fix race condition in espintcp_close() T...
CVE-2026-22627HIGH8.8A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiSwitchAXFixed 1....
CVE-2026-22572HIGH7.2An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3,...
CVE-2026-21262HIGH8.8Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-20967HIGH8.8Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a...
CVE-2026-1261HIGH7.2The MetForm Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Quiz feature in all versions u...
CVE-2026-3585HIGH7.5The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15....
CVE-2026-30925HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.0-a...
CVE-2026-30920HIGH8.6OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback t...
CVE-2026-30917HIGH8.8Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to 2.1.1, a stored XSS can be i...
CVE-2026-2364HIGH7.3If a legitimate user confirms a self-update prompt or initiate an installation of a CODESYS Development System, a low pr...
CVE-2026-28513HIGH7.1Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.4.0, th...
CVE-2026-28281HIGH7.1InstantCMS is a free and open source content management system. Prior to 2.18.1, InstantCMS does not validate CSRF token...
CVE-2026-27689HIGH7.7Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular us...
CVE-2026-30931HIGH7.8ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-30929HIGH7.8ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-30926HIGH7.1SiYuan is a personal knowledge management system. Prior to 3.5.10, a privilege escalation vulnerability exists in the pu...
CVE-2026-30883HIGH7.8ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-28693HIGH8.1ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-28691HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-28494HIGH7.1ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-28432HIGH7.5Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerabilit...
CVE-2026-28431HIGH7.5Misskey is an open source, federated social media platform. All Misskey servers running versions 8.45.0 and later, but p...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now