2026 CVE Vulnerabilities

55,812 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-23939HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in hexpm hexpm/hexpm ('Elix...
CVE-2026-1565HIGH8.8The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP...
CVE-2026-1241HIGH8.7The Pelco, Inc. Sarix Professional 3 Series Cameras are vulnerable to an authentication bypass issue in their web manage...
CVE-2026-26938HIGH7.7Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which cou...
CVE-2026-26937HIGH7.5Uncontrolled Resource Consumption (CWE-400) in the Timelion component in Kibana can lead Denial of Service via Input Dat...
CVE-2026-26936HIGH7.5Inefficient Regular Expression Complexity (CWE-1333) in the AI Inference Anonymization Engine in Kibana can lead Denial ...
CVE-2026-26935HIGH7.5Improper Input Validation (CWE-20) in the internal Content Connectors search endpoint in Kibana can lead Denial of Servi...
CVE-2026-26932HIGH7.5Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service ...
CVE-2026-26682HIGH7.8An issue in fastCMS before v.0.1.6 allows a local attacker to execute arbitrary code via the PluginController.java compo...
CVE-2026-23750HIGH8.1Golioth Pouch version 0.1.0, prior to commit 1b2219a1, contains a heap-based buffer overflow in BLE GATT server certific...
CVE-2026-26265HIGH7.5Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an IDOR vulnerabil...
CVE-2026-26078HIGH7.5Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, when the `patreon_...
CVE-2026-3071HIGH8.4Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to ar...
CVE-2026-2244HIGH8.4A vulnerability in Google Cloud Vertex AI Workbench from 7/21/2025 to 01/30/2026 allows an attacker to exfiltrate valid ...
CVE-2026-1198HIGH8.6SIMPLE.ERP is vulnerable to the SQL Injection in search functionality in "Obroty na kontach" window. Lack of input valid...
CVE-2026-28138HIGH7.2Deserialization of Untrusted Data vulnerability in Stylemix uListing ulisting allows Object Injection.This issue affects...
CVE-2026-28136HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs WP SMS ...
CVE-2026-1693HIGH7.5The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVu...
CVE-2026-25191HIGH8.4The installer of FinalCode Client provided by Digital Arts Inc. contains an issue with the DLL search path. If a user is...
CVE-2026-23703HIGH8.5The installer of FinalCode Client provided by Digital Arts Inc. contains an incorrect default permissions vulnerability....
CVE-2026-1311HIGH8.8The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 ...
CVE-2026-1779HIGH8.1The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and in...
CVE-2026-27969HIGH8.8Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with...
CVE-2026-27961HIGH8.8Agenta is an open-source LLMOps platform. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior...
CVE-2026-27959HIGH7.5Koa is middleware for Node.js using ES2017 async functions. Prior to versions 3.1.2 and 2.16.4, Koa's `ctx.hostname` API...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now