2026 CVE Vulnerabilities

56,309 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-20979HIGH7.8Improper privilege management in Settings prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary act...
CVE-2026-1756HIGH8.8The WP FOFT Loader plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in...
CVE-2026-24512HIGH8.8A security issue was discovered in ingress-nginx where the `rules.http.paths.path` Ingress field can be used to inject c...
CVE-2026-1580HIGH8.8A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-method` Ingress annotation ...
CVE-2026-25510HIGH8.8CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-25223HIGH7.5Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.2, a validation bypass vulnerability...
CVE-2026-25155HIGH7.1Qwik is a performance focused javascript framework. Prior to version 1.12.0, a typo in the regular expression within isC...
CVE-2026-1811HIGH8.8A flaw has been found in bolo-blog bolo-solo up to 2.6.4. This affects the function importFromMarkdown of the file src/m...
CVE-2026-24887HIGH8.8Claude Code is an agentic coding tool. Prior to version 2.0.72, due to an error in command parsing, it was possible to b...
CVE-2026-24052HIGH7.4Claude Code is an agentic coding tool. Prior to version 1.0.111, Claude Code contained insufficient URL validation in it...
CVE-2026-1862HIGH8.8Type Confusion in V8 in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corr...
CVE-2026-1861HIGH8.8Heap buffer overflow in libvpx in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit...
CVE-2026-1810HIGH8.8A vulnerability was detected in bolo-blog bolo-solo up to 2.6.4. The impacted element is the function unpackFilteredZip ...
CVE-2026-25615HIGH7.2Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5668.
CVE-2026-25614HIGH7.5Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5680.
CVE-2026-24149HIGH7.8NVIDIA Megatron-LM for all platforms contains a vulnerability in a script, where malicious data created by an attacker m...
CVE-2026-1803HIGH8.2A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the component Dropbear ...
CVE-2026-25503HIGH7.1iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color ...
CVE-2026-25502HIGH7.8iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color ...
CVE-2026-25239HIGH7.5PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulner...
CVE-2026-25235HIGH7.5PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, predictable verificati...
CVE-2026-1802HIGH7.3A security flaw has been discovered in Ziroom ZHOME A0101 1.0.1.0. This issue affects the function macAddrClone of the f...
CVE-2026-24773HIGH7.5The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, ...
CVE-2026-24669HIGH7.8The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, ...
CVE-2026-24762HIGH7.5RustFS is a distributed object storage system built in Rust. From versions alpha.13 to alpha.81, RustFS logs sensitive c...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now