2026 CVE Vulnerabilities

56,187 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-1714HIGH8.6The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is...
CVE-2026-23599HIGH7.8A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking ClearPass OnGuard Software fo...
CVE-2026-22048HIGH7.1StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and con...
CVE-2026-26119HIGH8.8Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
CVE-2026-2629HIGH7.3A weakness has been identified in jishi node-sonos-http-api up to 3776f0ee2261c924c7b7204de121a38100a08ca7. Affected is ...
CVE-2026-2627HIGH7.8A security flaw has been discovered in Softland FBackup up to 9.9. This impacts an unknown function in the library C:\Pr...
CVE-2026-2623HIGH8.8A flaw has been found in Blossom up to 1.17.1. This issue affects the function put of the file blossom-backend/common/co...
CVE-2026-2621HIGH7.3A security vulnerability has been detected in Sciyon Koyuan Thermoelectricity Heat Network Management System 3.0. This a...
CVE-2026-23595HIGH8.8An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote at...
CVE-2026-2620HIGH7.3A weakness has been identified in Huace Monitoring and Early Warning System 2.2. Affected by this issue is some unknown ...
CVE-2026-22284HIGH7.2Dell SmartFabric OS10 Software, versions prior to 10.5.6.12, contains an Improper Neutralization of Special Elements use...
CVE-2026-2630HIGH8.8A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the und...
CVE-2026-26736HIGH8.8TOTOLINK A3002RU_V3 V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the static_ipv6 pa...
CVE-2026-26732HIGH8.8TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the vpnUser or vpnPas...
CVE-2026-26731HIGH8.8TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`param...
CVE-2026-24734HIGH7.5Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Na...
CVE-2026-2618HIGH7.4A vulnerability was determined in Beetel 777VR1 up to 01.00.09. This impacts an unknown function of the component SSH Se...
CVE-2026-23648HIGH8.5Glory RBG-100 recycler systems using the ISPK-08 software component contain multiple system binaries with overly permiss...
CVE-2026-2617HIGH8.8A vulnerability was found in Beetel 777VR1 up to 01.00.09. This affects an unknown function of the component Telnet Serv...
CVE-2026-25087HIGH7Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It ca...
CVE-2026-2615HIGH7.3A flaw has been found in Wavlink WL-NU516U1 up to 20251208. The affected element is the function singlePortForwardDelete...
CVE-2026-2247HIGH8.3SQL injection vulnerability (SQLi) in Clicldeu SaaS, specifically in the generation of reports, which occurs when a prev...
CVE-2026-1216HIGH7.2The RSS Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'template' parameter in ...
CVE-2026-2592HIGH7.7The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Upd...
CVE-2026-2474HIGH7.5Crypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable to a heap buffer overflow in the XS function crypt_...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now