2026 CVE Vulnerabilities

55,784 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-0869HIGH8.8Authentication bypass in Brocade ASCG 3.4.0 Could allow an unauthorized user to perform ASCG operations related to Broca...
CVE-2026-3437HIGH7.8An improper restriction of operations within the bounds of a memory buffer vulnerability in Portwell Engineering Toolkit...
CVE-2026-2637HIGH7.8iBoysoft NTFS for Mac contains a local privilege escalation vulnerability in its privileged helper daemon ntfshelperd. T...
CVE-2026-28518HIGH8.4OpenViking versions 0.2.1 and prior, fixed in commit 46b3e76, contain a path traversal vulnerability in the .ovpack impo...
CVE-2026-25673HIGH7.5An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django ...
CVE-2026-20777HIGH8.1A heap-based buffer overflow vulnerability exists in the Nicolet WFT parsing functionality of The Biosig Project libbios...
CVE-2026-3342HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an authenticated privileged administrator to ex...
CVE-2026-3463HIGH7.8A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::binary_writer:...
CVE-2026-2568HIGH7.2The WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin for WordPress is vulnerable to ...
CVE-2026-1876HIGH7.5Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET/IP Et...
CVE-2026-1875HIGH7.5Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-EIP EtherN...
CVE-2026-1874HIGH7.5Always-Incorrect Control Flow Implementation vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENE...
CVE-2026-2448HIGH8.8The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc...
CVE-2026-2269HIGH7.2The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnera...
CVE-2026-0754HIGH8.2An embedded test key and certificate could be extracted from a Poly Voice device using specialized reverse engineering t...
CVE-2026-1566HIGH8.8The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to privilege esca...
CVE-2026-3338HIGH8.7Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verificatio...
CVE-2026-3337HIGH8.2Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine au...
CVE-2026-3336HIGH8.7Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain v...
CVE-2026-27596HIGH7.5Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada...
CVE-2026-25884HIGH8.1Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada...
CVE-2026-21882HIGH8.4theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to versi...
CVE-2026-21853HIGH8.8AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.25.4, there is a one-click re...
CVE-2026-0047HIGH8.4In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due...
CVE-2026-0038HIGH8.4In multiple functions of mem_protect.c, there is a possible way to execute arbitrary code due to a logic error in the co...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now