2026 CVE Vulnerabilities

55,909 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-24892HIGH8.8openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheu...
CVE-2026-2855HIGH8.8A vulnerability has been found in D-Link DWR-M960 1.01.07. Affected is the function sub_4648F0 of the file /boafrm/formD...
CVE-2026-2854HIGH8.8A flaw has been found in D-Link DWR-M960 1.01.07. This impacts the function sub_4611CC of the file /boafrm/formNtp of th...
CVE-2026-2853HIGH8.8A vulnerability was detected in D-Link DWR-M960 1.01.07. This affects the function sub_462E14 of the file /boafrm/formSy...
CVE-2026-2473HIGH7.7Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not includin...
CVE-2026-2472HIGH8.6Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-clo...
CVE-2026-27115HIGH7.1ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below have an unvalidated command-line argument t...
CVE-2026-24891HIGH7.5openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheu...
CVE-2026-2818HIGH8.2A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write f...
CVE-2026-26746HIGH8.8OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An atta...
CVE-2026-26724HIGH7.6Cross Site Scripting vulnerability in Key Systems Inc Global Facilities Management Software v. 20230721a allows a remote...
CVE-2026-26723HIGH8.2Cross Site Scripting vulnerability in Key Systems Inc Global Facilities Management Software v. 20230721a allows a remote...
CVE-2026-26721HIGH7.1An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to obtain sensiti...
CVE-2026-26102HIGH7.8Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network...
CVE-2026-26101HIGH7.8Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network...
CVE-2026-26048HIGH7.5The Wi-Fi router is vulnerable to de-authentication attacks due to the absence of management frame protection, allowing...
CVE-2026-24790HIGH8.2The underlying PLC of the device can be remotely influenced, without proper safeguards or authentication.
CVE-2026-24455HIGH7.5The embedded web interface of the device does not support HTTPS/TLS for authentication and uses HTTP Basic Authenticati...
CVE-2026-2847HIGH7.3A vulnerability was detected in UTT HiPER 520 1.7.7-160105. Affected is the function sub_44EFB4 of the file /goform/form...
CVE-2026-2846HIGH7.3A security vulnerability has been detected in UTT HiPER 520 1.7.7-160105. This impacts the function sub_44D264 of the fi...
CVE-2026-27072HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PixelYourSite Pixe...
CVE-2026-24959HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help De...
CVE-2026-24955HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fox-themes Whizz P...
CVE-2026-24950HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in themeplugs Authorsy authorsy allows Exploiting Incorre...
CVE-2026-24949HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods PhotoMe...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now