2026 CVE Vulnerabilities

56,102 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-24743HIGH7.5InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site ...
CVE-2026-2668HIGH7.3A vulnerability was found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This affects an...
CVE-2026-24746HIGH7.5InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site ...
CVE-2026-2666HIGH7.2A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTem...
CVE-2026-2662HIGH7.8A weakness has been identified in FascinatedBox lily up to 2.3. This vulnerability affects the function count_transforms...
CVE-2026-2661HIGH7.8A security flaw has been discovered in Squirrel up to 3.2. This affects the function SQObjectPtr::operator in the librar...
CVE-2026-23491HIGH7.5InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A path traversal vul...
CVE-2026-0875HIGH7.8A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulner...
CVE-2026-0874HIGH7.8A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vuln...
CVE-2026-2660HIGH7.8A vulnerability was identified in FascinatedBox lily up to 2.3. Affected by this issue is the function shorthash_for_nam...
CVE-2026-22860HIGH7.5Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check...
CVE-2026-2659HIGH7.8A vulnerability was determined in Squirrel up to 3.2. Affected by this vulnerability is the function SQFuncState::PopTar...
CVE-2026-24708HIGH8.2An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious ...
CVE-2026-2507HIGH8.7When BIG-IP AFM or BIG-IP DDoS is provisioned, undisclosed traffic can cause TMM to terminate.  Note: Software versions ...
CVE-2026-23227HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/exynos: vidi: use ctx->lock to protect struct v...
CVE-2026-23226HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: add chann_lock to protect ksmbd_chann_list x...
CVE-2026-23225HIGH7.8In the Linux kernel, the following vulnerability has been resolved: sched/mmcid: Don't assume CID is CPU owned on mode ...
CVE-2026-23224HIGH7.8In the Linux kernel, the following vulnerability has been resolved: erofs: fix UAF issue for file-backed mounts w/ dire...
CVE-2026-23223HIGH7.8In the Linux kernel, the following vulnerability has been resolved: xfs: fix UAF in xchk_btree_check_block_owner We ca...
CVE-2026-23221HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bus: fsl-mc: fix use-after-free in driver_override_...
CVE-2026-27099HIGH8Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-prov...
CVE-2026-23216HIGH7.8In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix use-after-free in iscsit_d...
CVE-2026-1426HIGH8.8The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and ...
CVE-2026-2464HIGH8.7Path traversal vulnerability in the AMR Printer Management 1.01 Beta web service, which allows remote attackers to read ...
CVE-2026-2653HIGH7.8A security flaw has been discovered in admesh up to 0.98.5. This issue affects the function stl_check_normal_vector of t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now