2026 CVE Vulnerabilities

56,318 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-25027HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-25022HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design Kivi...
CVE-2026-24954HIGH8.8Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This...
CVE-2026-1285HIGH7.5An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `django.utils.text.Truncator.char...
CVE-2026-1730HIGH8.8The OS DataHub Maps plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation i...
CVE-2026-1375HIGH8.1The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere...
CVE-2026-22550HIGH8.8OS command injection vulnerability exists in ELECOM wireless LAN products. A crafted request from a logged-in user may l...
CVE-2026-1065HIGH7.2The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inc...
CVE-2026-1058HIGH7.1The Form Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via hidden field values in all versions...
CVE-2026-0617HIGH7.2The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2026-24694HIGH8.4The installer for Roland Cloud Manager ver.3.1.19 and prior insecurely loads Dynamic Link Libraries (DLLs), which could ...
CVE-2026-0383HIGH7.8A vulnerability in Brocade Fabric OS could allow an authenticated, local attacker with privileges to access the Bash she...
CVE-2026-25222HIGH7.5PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, a timing attack vulnerability in ...
CVE-2026-25221HIGH8.1PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, the OAuth 2.0 implementation for ...
CVE-2026-25134HIGH8.8Group-Office is an enterprise customer relationship management and groupware tool. Prior to 6.8.150, 25.0.82, and 26.0.5...
CVE-2026-25060HIGH8.1OpenList Frontend is a UI component for OpenList. Prior to 4.1.10, certificate verification is disabled by default for a...
CVE-2026-25059HIGH8.8OpenList Frontend is a UI component for OpenList. Prior to 4.1.10, the application contains path traversal vulnerability...
CVE-2026-24763HIGH8.8OpenClaw (formerly Clawdbot) is a personal AI assistant you run on your own devices. Prior to 2026.1.29, a command inje...
CVE-2026-24737HIGH8.1jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acrofor...
CVE-2026-24051HIGH7OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulner...
CVE-2026-23515HIGH8.8Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulner...
CVE-2026-1778HIGH8.2Amazon SageMaker Python SDK before v3.1.1 or v2.256.0 disables TLS certificate verification for HTTPS connections made b...
CVE-2026-1777HIGH8.5The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 includes the ModelBuilder HMAC signing key in the cleartext r...
CVE-2026-0924HIGH7BuhoCleaner contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root ...
CVE-2026-22229HIGH7.2A command injection vulnerability may be exploited after the admin's authentication via the import of a crafted VPN clie...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now