2026 CVE Vulnerabilities

43,297 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-66473HIGH7.5Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
CVE-2026-65447HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
CVE-2026-65446HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.
CVE-2026-65443HIGH7.1Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.
CVE-2026-65442HIGH7.2Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
CVE-2026-65441HIGH7.1Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.
CVE-2026-65440HIGH7.1Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.
CVE-2026-65439HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.
CVE-2026-65438HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.
CVE-2026-65437HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.
CVE-2026-61957HIGH7.1Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.
CVE-2026-61953HIGH7.2Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
CVE-2026-55685HIGH7.5React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauth...
CVE-2026-51078HIGH7.5An issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the str parameter of the fil...
CVE-2026-51077HIGH7.5SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the sqlqu...
CVE-2026-64783HIGH8.8A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and i...
CVE-2026-64768HIGH8.1An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26....
CVE-2026-64766HIGH7.8An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS...
CVE-2026-64765HIGH7.8An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS...
CVE-2026-64764HIGH7.8An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26....
CVE-2026-64763HIGH7.8An out-of-bounds write issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.6 and iPadOS 2...
CVE-2026-64758HIGH7.8The issue was addressed with improved bounds checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, ...
CVE-2026-64757HIGH8.8A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and...
CVE-2026-64749HIGH7.8The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15...
CVE-2026-64747HIGH7.8A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Se...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now