2026 CVE Vulnerabilities

56,102 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-2644HIGH7.8A weakness has been identified in niklasso minisat up to 2.2.0. This issue affects the function Solver::value in the lib...
CVE-2026-2296HIGH7.2The Product Addons for Woocommerce – Product Options with Custom Fields plugin for WordPress is vulnerable to Code Injec...
CVE-2026-2019HIGH7.2The Cart All In One For WooCommerce plugin for WordPress is vulnerable to Code Injection in all versions up to, and incl...
CVE-2026-1937HIGH7.2The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized modification of data that ...
CVE-2026-1368HIGH7.5The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification ...
CVE-2026-2576HIGH7.5The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based ...
CVE-2026-1931HIGH7.2The Rent Fetch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'keyword' parameter in all vers...
CVE-2026-1714HIGH8.6The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is...
CVE-2026-23599HIGH7.8A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking ClearPass OnGuard Software fo...
CVE-2026-22048HIGH7.1StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and con...
CVE-2026-26119HIGH8.8Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
CVE-2026-2629HIGH7.3A weakness has been identified in jishi node-sonos-http-api up to 3776f0ee2261c924c7b7204de121a38100a08ca7. Affected is ...
CVE-2026-2627HIGH7.8A security flaw has been discovered in Softland FBackup up to 9.9. This impacts an unknown function in the library C:\Pr...
CVE-2026-2623HIGH8.8A flaw has been found in Blossom up to 1.17.1. This issue affects the function put of the file blossom-backend/common/co...
CVE-2026-2621HIGH7.3A security vulnerability has been detected in Sciyon Koyuan Thermoelectricity Heat Network Management System 3.0. This a...
CVE-2026-23595HIGH8.8An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote at...
CVE-2026-2620HIGH7.3A weakness has been identified in Huace Monitoring and Early Warning System 2.2. Affected by this issue is some unknown ...
CVE-2026-22284HIGH7.2Dell SmartFabric OS10 Software, versions prior to 10.5.6.12, contains an Improper Neutralization of Special Elements use...
CVE-2026-2630HIGH8.8A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the und...
CVE-2026-26736HIGH8.8TOTOLINK A3002RU_V3 V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the static_ipv6 pa...
CVE-2026-26732HIGH8.8TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the vpnUser or vpnPas...
CVE-2026-26731HIGH8.8TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`param...
CVE-2026-24734HIGH7.5Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Na...
CVE-2026-2618HIGH7.4A vulnerability was determined in Beetel 777VR1 up to 01.00.09. This impacts an unknown function of the component SSH Se...
CVE-2026-23648HIGH8.5Glory RBG-100 recycler systems using the ISPK-08 software component contain multiple system binaries with overly permiss...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now