2026 CVE Vulnerabilities

55,810 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-27752HIGH8.2SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, al...
CVE-2026-26862HIGH8.3CleverTap Web SDK version 1.15.2 and earlier is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessag...
CVE-2026-26861HIGH8.3CleverTap Web SDK version 1.15.2 and earlier is vulnerable to Cross-Site Scripting (XSS) via window.postMessage. The han...
CVE-2026-21619HIGH7.5Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), ...
CVE-2026-25147HIGH7.1OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio...
CVE-2026-3304HIGH7.5Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allo...
CVE-2026-2749HIGH8.8Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue aff...
CVE-2026-2359HIGH7.5Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allo...
CVE-2026-3223HIGH7.8Arbitrary file write & potential privilege escalation exploiting zip slip vulnerability in Google Web Designer.
CVE-2026-2252HIGH7.5An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via craft...
CVE-2026-1627HIGH8.1An attacker may exploit the use of outdated and weak MAC algorithms in the device’s SSH service to potentially compromis...
CVE-2026-27776HIGH8.8IM-LogicDesigner module of intra-mart Accel Platform contains insecure deserialization issue. This can be exploited only...
CVE-2026-0980HIGH8.8A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An...
CVE-2026-28372HIGH7.8telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service creden...
CVE-2026-3292HIGH8.8A security vulnerability has been detected in jizhiCMS up to 2.5.6. Affected is the function findAll in the library frph...
CVE-2026-1442HIGH7.8Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an a...
CVE-2026-2428HIGH7.5The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in...
CVE-2026-28364HIGH7.8In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables re...
CVE-2026-28363HIGH8.8In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviation...
CVE-2026-3285HIGH7.8A vulnerability was determined in berry-lang berry up to 1.1.0. The affected element is the function scan_string of the ...
CVE-2026-3283HIGH7.1A vulnerability has been found in libvips 8.19.0. This issue affects the function vips_extract_band_build of the file li...
CVE-2026-3282HIGH7.1A flaw has been found in libvips 8.19.0. This vulnerability affects the function vips_unpremultiply_build of the file li...
CVE-2026-3281HIGH7.8A vulnerability was detected in libvips 8.19.0. This affects the function vips_bandrank_build of the file libvips/conver...
CVE-2026-3275HIGH8.8A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromAddressNat of the file /goform/addre...
CVE-2026-3274HIGH8.8A security flaw has been discovered in Tenda F453 1.0.0.3. Affected by this issue is the function frmL7ProtForm of the f...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now