2026 CVE Vulnerabilities

55,766 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-28773HIGH8.8The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series Sup...
CVE-2026-28770HIGH8.8Improper neutralization of special elements in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corp...
CVE-2026-2025HIGH7.5The Mail Mint WordPress plugin before 1.19.5 does not have authorization in one of its REST API endpoint, allowing unau...
CVE-2026-3452HIGH7.2Concrete CMS below version 9.4.8 is vulnerable to Remote Code Execution by stored PHP object injection into the Express ...
CVE-2026-1945HIGH7.2The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_ema...
CVE-2026-1273HIGH7.2The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Server-S...
CVE-2026-28289HIGH8.1FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-...
CVE-2026-27981HIGH7.4HomeBox is a home inventory and organization system. Prior to 0.24.0, the authentication rate limiter (authRateLimiter) ...
CVE-2026-27932HIGH7.5joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar...
CVE-2026-27905HIGH7.8BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4....
CVE-2026-27622HIGH7.8OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-3487HIGH7.2A vulnerability was found in itsourcecode College Management System 1.0. This issue affects some unknown processing of t...
CVE-2026-25146HIGH8.1OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to b...
CVE-2026-1775HIGH8.8The Labkotec LID-3300IP has an existing vulnerability in the ice detector software that enables an unauthenticated attac...
CVE-2026-3486HIGH7.2A vulnerability has been found in itsourcecode College Management System 1.0. This vulnerability affects unknown code of...
CVE-2026-25906HIGH7.8Dell Optimizer, versions prior to 6.3.1, contain an Improper Link Resolution Before File Access ('Link Following') vulne...
CVE-2026-24502HIGH7.8Dell Command | Intel vPro Out of Band, versions prior to 4.7.0, contain an Uncontrolled Search Path Element vulnerabilit...
CVE-2026-1567HIGH7.5IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere...
CVE-2026-3484HIGH8.8A vulnerability was detected in PhialsBasement nmap-mcp-server up to bee6d23547d57ae02460022f7c78ac0893092e38. Affected ...
CVE-2026-2915HIGH7.1HP System Event Utility might allow denial of service with elevated arbitrary file writes. This potential vulnerability ...
CVE-2026-29022HIGH7.8dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in th...
CVE-2026-26892HIGH7.2Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_carrier.php.
CVE-2026-0869HIGH8.8Authentication bypass in Brocade ASCG 3.4.0 Could allow an unauthorized user to perform ASCG operations related to Broca...
CVE-2026-3437HIGH7.8An improper restriction of operations within the bounds of a memory buffer vulnerability in Portwell Engineering Toolkit...
CVE-2026-2637HIGH7.8iBoysoft NTFS for Mac contains a local privilege escalation vulnerability in its privileged helper daemon ntfshelperd. T...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now