2026 CVE Vulnerabilities

43,308 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-59534HIGH7.5Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
CVE-2026-59532HIGH7.5Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.
CVE-2026-59531HIGH7.5Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.
CVE-2026-59530HIGH7.5Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
CVE-2026-59529HIGH7.5Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
CVE-2026-59528HIGH7.5Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.
CVE-2026-65878HIGH8.3Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path valida...
CVE-2026-65877HIGH8.2Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of var...
CVE-2026-59690HIGH8A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection M...
CVE-2026-59689HIGH8An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connectio...
CVE-2026-59688HIGH8.4An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection M...
CVE-2026-59687HIGH8.4An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection M...
CVE-2026-59686HIGH8.4An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection M...
CVE-2026-12991HIGH8.7The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Visio...
CVE-2026-12990HIGH7.7An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simul...
CVE-2026-12989HIGH8.7A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated at...
CVE-2026-58389HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects A...
CVE-2026-55969HIGH7.5Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This i...
CVE-2026-55968HIGH7.5Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift ...
CVE-2026-49158HIGH7.5Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This iss...
CVE-2026-48586HIGH7.5Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D...
CVE-2026-48145HIGH7.5Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects A...
CVE-2026-45112HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects A...
CVE-2026-43871HIGH7.5Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings....
CVE-2026-41608HIGH7.5Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This i...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now