2026 CVE Vulnerabilities

55,833 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-3201HIGH7.5USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
CVE-2026-27692HIGH7.1iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and inclu...
CVE-2026-25701HIGH7An Insecure Temporary File vulnerability in openSUSE sdbootutil allows local users to pre-create a directory to achieve ...
CVE-2026-26103HIGH7.1A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encrypti...
CVE-2026-2416HIGH7.5The Geo Mashup plugin for WordPress is vulnerable to SQL Injection via the 'sort' parameter in all versions up to, and i...
CVE-2026-1929HIGH8.8The Advanced Woo Labels plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including...
CVE-2026-1916HIGH7.5The WPGSI: Spreadsheet Integration plugin for WordPress is vulnerable to unauthorized modification and loss of data due ...
CVE-2026-3169HIGH8.8A security vulnerability has been detected in Tenda F453 1.0.0.3. This impacts the function fromSafeEmailFilter of the f...
CVE-2026-3168HIGH8.8A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromNatStaticSetting of the file /goform...
CVE-2026-3167HIGH8.8A security flaw has been discovered in Tenda F453 1.0.0.3. The impacted element is the function formWebTypeLibrary of th...
CVE-2026-3166HIGH8.8A vulnerability was identified in Tenda F453 1.0.0.3. The affected element is the function fromRouteStatic of the file /...
CVE-2026-3179HIGH8.1The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listi...
CVE-2026-3165HIGH8.8A vulnerability was determined in Tenda F453 1.0.0.3. Impacted is the function fromSetWifiGusetBasic of the file /goform...
CVE-2026-3163HIGH7.5A vulnerability has been found in SourceCodester Website Link Extractor 1.0. This vulnerability affects the function fil...
CVE-2026-3150HIGH8.8A security vulnerability has been detected in itsourcecode College Management System 1.0. This affects an unknown part o...
CVE-2026-3149HIGH8.8A weakness has been identified in itsourcecode College Management System 1.0. Affected by this issue is some unknown fun...
CVE-2026-27696HIGH8.6changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, changedetection.io...
CVE-2026-3147HIGH7.8A vulnerability was found in libvips up to 8.18.0. This affects the function vips_foreign_load_csv_build of the file lib...
CVE-2026-27747HIGH8.8The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated SQL injection vulnerability...
CVE-2026-27745HIGH8.8The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated remote code execution vulne...
CVE-2026-27640HIGH7.5tfplan2md is software for converting Terraform plan JSON files into human-readable Markdown reports. Prior to version 1....
CVE-2026-27636HIGH8.8FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's...
CVE-2026-3145HIGH7.8A flaw has been found in libvips up to 8.18.0. The affected element is the function vips_foreign_load_matrix_file_is_a/v...
CVE-2026-27629HIGH8.8InvenTree is an Open Source Inventory Management System. Prior to version 1.2.3, insecure server-side templates can be h...
CVE-2026-27628HIGH7.5pypdf is a free and open-source pure-python PDF library. Prior to 6.7.2, an attacker who uses this vulnerability can cra...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now