2026 CVE Vulnerabilities

56,095 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-25378HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nel...
CVE-2026-25326HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-25316HIGH7.2Deserialization of Untrusted Data vulnerability in Brainstorm Force CartFlows cartflows allows Object Injection.This iss...
CVE-2026-23805HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yoren Chang Media ...
CVE-2026-23547HIGH7.1Missing Authorization vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows Exploit...
CVE-2026-23544HIGH8.8Deserialization of Untrusted Data vulnerability in codetipi Valenti valenti allows Object Injection.This issue affects V...
CVE-2026-23541HIGH7.5Missing Authorization vulnerability in WPFunnels Mail Mint mail-mint allows Accessing Functionality Not Properly Constra...
CVE-2026-22333HIGH7.2Deserialization of Untrusted Data vulnerability in YITHEMES YITH WooCommerce Compare yith-woocommerce-compare allows Obj...
CVE-2026-2706HIGH7.5A flaw has been found in code-projects Patient Record Management System 1.0. This affects an unknown function of the fil...
CVE-2026-2705HIGH8.1A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in ...
CVE-2026-2704HIGH8.1A security vulnerability has been detected in Open Babel up to 3.1.1. The affected element is the function OpenBabel::tr...
CVE-2026-25474HIGH7.5OpenClaw is a personal AI assistant. In versions 2026.1.30 and below, if channels.telegram.webhookSecret is not set when...
CVE-2026-25232HIGH8.8Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have an access control bypass vulnerability wh...
CVE-2026-0974HIGH8.8The Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin plugin for WordPress is vulnerable ...
CVE-2026-0912HIGH8.8The Toret Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege esc...
CVE-2026-25926HIGH7.3Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions...
CVE-2026-24745HIGH7.5InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site ...
CVE-2026-2670HIGH7.2A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6...
CVE-2026-2650HIGH8.8Heap buffer overflow in Media in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potentially exploit ...
CVE-2026-2649HIGH8.8Integer overflow in V8 in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potentially exploit heap co...
CVE-2026-2648HIGH8.8Heap buffer overflow in PDFium in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to perform an out of b...
CVE-2026-27182HIGH8.6Saturn Remote Mouse Server contains a command injection vulnerability that allows unauthenticated attackers to execute a...
CVE-2026-27181HIGH8.7MajorDoMo (aka Major Domestic Module) allows unauthenticated arbitrary module uninstallation through the market module. ...
CVE-2026-24744HIGH7.5InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site ...
CVE-2026-24743HIGH7.5InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now