2026 CVE Vulnerabilities

56,195 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-25108HIGH8.8FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user...
CVE-2026-26225HIGH8.5Intego Personal Backup, a macOS backup utility that allows users to create scheduled backups and bootable system clones,...
CVE-2026-26224HIGH8.5Intego Log Reporter, a macOS diagnostic utility bundled with Intego security products that collects system and applicati...
CVE-2026-26076HIGH7.5ntpd-rs is a full-featured implementation of the Network Time Protocol. Prior to 1.7.1, an attacker can remotely induce ...
CVE-2026-26069HIGH7.5Scraparr is a Prometheus Exporter for various components of the *arr Suite. From 3.0.0-beta to before 3.0.2, when the Re...
CVE-2026-26056HIGH8.8Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in ...
CVE-2026-26055HIGH7.5Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in ...
CVE-2026-26020HIGH8.8AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut...
CVE-2026-25949HIGH7.5Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managi...
CVE-2026-25922HIGH8.8authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source tha...
CVE-2026-25767HIGH8.1LavinMQ is a high-performance message queue & streaming server. Before 2.6.8, an authenticated user, with the “Policymak...
CVE-2026-25748HIGH7.5authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible...
CVE-2026-25227HIGH7.2authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using de...
CVE-2026-24894HIGH7.5FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSIO...
CVE-2026-21435HIGH7.5webtransport-go is an implementation of the WebTransport protocol. Prior to v0.10.0, an attacker can cause a denial of s...
CVE-2026-21434HIGH7.5webtransport-go is an implementation of the WebTransport protocol. From 0.3.0 to 0.9.0, an attacker can cause excessive ...
CVE-2026-26217HIGH7.5Crawl4AI versions prior to 0.8.0 contain a local file inclusion vulnerability in the Docker API deployment. The /execute...
CVE-2026-1104HIGH8.8The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creatio...
CVE-2026-2007HIGH8.2Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string....
CVE-2026-2006HIGH8.8Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted...
CVE-2026-2005HIGH8.8Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating syst...
CVE-2026-2004HIGH8.8Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object cre...
CVE-2026-1320HIGH7.2The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2026-1316HIGH7.2The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'media[]....
CVE-2026-2327HIGH7.5Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now