2026 CVE Vulnerabilities

56,076 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-22267HIGH8.8Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A...
CVE-2026-22266HIGH8.8Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communicat...
CVE-2026-27052HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-26362HIGH8.1Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Relative Path Traversal vulnerability. A low privileged attac...
CVE-2026-26360HIGH8.1Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low p...
CVE-2026-26359HIGH8.8Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low p...
CVE-2026-26358HIGH8.8Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Missing Authorization vulnerability. A low privileged attacke...
CVE-2026-25418HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bit Apps Bit Form ...
CVE-2026-25378HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nel...
CVE-2026-25326HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-25316HIGH7.2Deserialization of Untrusted Data vulnerability in Brainstorm Force CartFlows cartflows allows Object Injection.This iss...
CVE-2026-23805HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yoren Chang Media ...
CVE-2026-23547HIGH7.1Missing Authorization vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows Exploit...
CVE-2026-23544HIGH8.8Deserialization of Untrusted Data vulnerability in codetipi Valenti valenti allows Object Injection.This issue affects V...
CVE-2026-23541HIGH7.5Missing Authorization vulnerability in WPFunnels Mail Mint mail-mint allows Accessing Functionality Not Properly Constra...
CVE-2026-22333HIGH7.2Deserialization of Untrusted Data vulnerability in YITHEMES YITH WooCommerce Compare yith-woocommerce-compare allows Obj...
CVE-2026-2706HIGH7.5A flaw has been found in code-projects Patient Record Management System 1.0. This affects an unknown function of the fil...
CVE-2026-2705HIGH8.1A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in ...
CVE-2026-2704HIGH8.1A security vulnerability has been detected in Open Babel up to 3.1.1. The affected element is the function OpenBabel::tr...
CVE-2026-25474HIGH7.5OpenClaw is a personal AI assistant. In versions 2026.1.30 and below, if channels.telegram.webhookSecret is not set when...
CVE-2026-25232HIGH8.8Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have an access control bypass vulnerability wh...
CVE-2026-0974HIGH8.8The Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin plugin for WordPress is vulnerable ...
CVE-2026-0912HIGH8.8The Toret Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege esc...
CVE-2026-25926HIGH7.3Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions...
CVE-2026-24745HIGH7.5InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now