2026 CVE Vulnerabilities

56,354 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-23743HIGH7.5Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, permali...
CVE-2026-24775HIGH7.3OpenProject is an open-source, web-based project management software. In the new editor for collaborative documents base...
CVE-2026-0750HIGH7.5Improper Verification of Cryptographic Signature vulnerability in Drupal Drupal Commerce Paybox Commerce Paybox on Drupa...
CVE-2026-24685HIGH8.8OpenProject is an open-source, web-based project management software. Versions prior to 16.6.6 and 17.0.2 have an arbitr...
CVE-2026-22243HIGH8.8EGroupware is a Web based groupware server written in PHP. A SQL Injection vulnerability exists in the core components o...
CVE-2026-1522HIGH7.5A weakness has been identified in Open5GS up to 2.7.6. This vulnerability affects the function sgwc_s5c_handle_modify_be...
CVE-2026-1521HIGH7.5A security flaw has been discovered in Open5GS up to 2.7.6. This affects the function sgwc_s5c_handle_bearer_resource_fa...
CVE-2026-1280HIGH7.5The Frontend File Manager Plugin for WordPress is vulnerable to unauthorized file sharing due to a missing capability ch...
CVE-2026-0844HIGH8.8The Simple User Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including...
CVE-2026-1400HIGH7.2The AI Engine – The Chatbot and AI Framework for WordPress plugin for WordPress is vulnerable to arbitrary file uploads ...
CVE-2026-0702HIGH7.5The VidShop – Shoppable Videos for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the 'f...
CVE-2026-0832HIGH7.3The New User Approve plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a...
CVE-2026-1514HIGH7.1Official Document Management System developed by 2100 Technology has a Incorrect Authorization vulnerability, allowing a...
CVE-2026-1506HIGH7.3A vulnerability was determined in D-Link DIR-615 4.10. Impacted is an unknown function of the file /adv_mac_filter.php o...
CVE-2026-1505HIGH7.3A vulnerability was found in D-Link DIR-615 4.10. This issue affects some unknown processing of the file /set_temp_nodes...
CVE-2026-24852HIGH8.1iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color ...
CVE-2026-24842HIGH8.2node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink en...
CVE-2026-24840HIGH8.8Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a hardcoded credential in th...
CVE-2026-21569HIGH7.9This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Cente...
CVE-2026-24783HIGH7.5soroban-fixed-point-math is a fixed-point math library for Soroban smart contacts. In versions 1.3.0 and 1.4.0, the `mul...
CVE-2026-24779HIGH7.1vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.14.1, a Server-Side Request...
CVE-2026-24765HIGH7.8PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.6...
CVE-2026-24748HIGH7.2Kargo manages and automates the promotion of software artifacts. Prior to versions 1.8.7, 1.7.7, and 1.6.3, a bug was fo...
CVE-2026-24747HIGH8.8PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `wei...
CVE-2026-24741HIGH8.1ConvertXis a self-hosted online file converter. In versions prior to 0.17.0, the `POST /delete` endpoint uses a user-con...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now