2026 CVE Vulnerabilities

55,919 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-26202HIGH7.5Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user c...
CVE-2026-26201HIGH7.5emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 3.21.2, multiple shared maps are access...
CVE-2026-26200HIGH7.8HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 c...
CVE-2026-26189HIGH8.1Trivy Action runs Trivy as GitHub action to scan a Docker container image for vulnerabilities. A command injection vulne...
CVE-2026-26063HIGH8.8CediPay is a crypto-to-fiat app for the Ghanaian market. A vulnerability in CediPay prior to version 1.2.3 allows attack...
CVE-2026-26337HIGH8.8Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-s...
CVE-2026-2232HIGH7.5The Product Table and List Builder for WooCommerce Lite plugin for WordPress is vulnerable to time-based SQL Injection v...
CVE-2026-26336HIGH8.7Hyland Alfresco allows unauthenticated attackers to read arbitrary files from protected directories (like WEB-INF) via t...
CVE-2026-26016HIGH8.1Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1....
CVE-2026-25998HIGH7.5strongMan is a management interface for strongSwan, an OpenSource IPsec-based VPN. When storing credentials in the datab...
CVE-2026-24834HIGH8.8Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th...
CVE-2026-1581HIGH7.5The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all version...
CVE-2026-2274HIGH8.5A SSRF and Arbitrary File Read vulnerability in AppSheet Core in Google AppSheet prior to 2025-11-23 allows an authentic...
CVE-2026-26345HIGH8.6SPIP before 4.4.8 contains a stored cross-site scripting (XSS) vulnerability in the public area triggered in certain edg...
CVE-2026-25940HIGH8.1jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and methods of the Acrofor...
CVE-2026-25755HIGH8.8jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method al...
CVE-2026-25535HIGH7.5jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argument of the `addImage` ...
CVE-2026-22267HIGH8.8Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A...
CVE-2026-22266HIGH8.8Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communicat...
CVE-2026-27052HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-26362HIGH8.1Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Relative Path Traversal vulnerability. A low privileged attac...
CVE-2026-26360HIGH8.1Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low p...
CVE-2026-26359HIGH8.8Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low p...
CVE-2026-26358HIGH8.8Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Missing Authorization vulnerability. A low privileged attacke...
CVE-2026-25418HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bit Apps Bit Form ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now