2026 CVE Vulnerabilities

56,236 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-0652HIGH8.8On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters ...
CVE-2026-0651HIGH7.8A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP ser...
CVE-2026-24885HIGH8Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a Cross-Site Request Forgery (CS...
CVE-2026-22153HIGH8.1An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6...
CVE-2026-21743HIGH7.2A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all ver...
CVE-2026-1603HIGH7.5An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to ...
CVE-2026-2268HIGH7.5The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin...
CVE-2026-25656HIGH8.5A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3), User Management Component (UMC) (All version...
CVE-2026-25655HIGH8.5A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP2). The affected application permits improper mo...
CVE-2026-24343HIGH8.8Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in Apache HertzBeat. This is...
CVE-2026-23720HIGH7.3A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512)....
CVE-2026-23719HIGH7.3A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512)....
CVE-2026-23718HIGH7.3A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512)....
CVE-2026-23717HIGH7.3A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512)....
CVE-2026-23716HIGH7.3A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512)....
CVE-2026-23715HIGH7.3A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512)....
CVE-2026-22923HIGH7.8A vulnerability has been identified in NX (All versions < V2512), NX (Managed Mode) (All versions < V2512). The affected...
CVE-2026-1866HIGH7.2The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via double HTML-entity encoding in ...
CVE-2026-2097HIGH8.8Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to u...
CVE-2026-2094HIGH8.8Docpedia developed by Flowring has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbi...
CVE-2026-2093HIGH8.7Docpedia developed by Flowring has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject ar...
CVE-2026-2260HIGH7.3A vulnerability was found in D-Link DCS-931L up to 1.13.0. This affects an unknown part of the file /goform/setSysAdmin....
CVE-2026-24322HIGH7.7SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks f...
CVE-2026-23689HIGH7.7Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular us...
CVE-2026-23687HIGH8.8SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtai...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now