2026 CVE Vulnerabilities

56,007 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-22357HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spencer Haws Link ...
CVE-2026-22356HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-22354HIGH8.8Deserialization of Untrusted Data vulnerability in Dotstore Woocommerce Category Banner Management banner-management-for...
CVE-2026-22352HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PersianScript Pers...
CVE-2026-22351HIGH7.5Missing Authorization vulnerability in Marcus (aka @msykes) WP FullCalendar wp-fullcalendar allows Exploiting Incorrectl...
CVE-2026-22346HIGH8.8Deserialization of Untrusted Data vulnerability in A WP Life Slider Responsive Slideshow – Image slider, Gallery slidesh...
CVE-2026-22345HIGH8.8Deserialization of Untrusted Data vulnerability in A WP Life Image Gallery – Lightbox Gallery, Responsive Photo Gallery,...
CVE-2026-22344HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-20761HIGH8.1A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in th...
CVE-2026-26050HIGH8.4The installer for ジョブログ集計/分析ソフトウェア RICOHジョブログ集計ツール versions prior to Ver.1.3.7 contains an issue with the DLL search pat...
CVE-2026-2824HIGH8.8A flaw has been found in Comfast CF-E7 2.6.0.9. This affects the function sub_441CF4 of the file /cgi-bin/mbox-config?me...
CVE-2026-2823HIGH8.8A vulnerability was detected in Comfast CF-E7 2.6.0.9. The impacted element is the function sub_41ACCC of the file /cgi-...
CVE-2026-2822HIGH8.8A security vulnerability has been detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the ...
CVE-2026-2821HIGH7.3A weakness has been identified in Fujian Smart Integrated Management Platform System up to 7.5. Impacted is an unknown f...
CVE-2026-26996HIGH7.5minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 ...
CVE-2026-2820HIGH7.3A security flaw has been discovered in Fujian Smart Integrated Management Platform System up to 7.5. This issue affects ...
CVE-2026-26990HIGH8.8LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below have a Time-Bas...
CVE-2026-26980HIGH7.5Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform ...
CVE-2026-26960HIGH7.1node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-control...
CVE-2026-26065HIGH8.8calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and ...
CVE-2026-26064HIGH8.8calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and ...
CVE-2026-26975HIGH8.8Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Vers...
CVE-2026-2435HIGH8.8Tanium addressed a SQL injection vulnerability in Asset.
CVE-2026-27001HIGH7.8OpenClaw is a personal AI assistant. Prior to version 2026.2.15, OpenClaw embedded the current working directory (worksp...
CVE-2026-26959HIGH7.8ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below fail to validate the integrity or authentic...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now