2026 CVE Vulnerabilities

56,974 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-16015MEDIUM6.3A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of ...
CVE-2026-8396HIGH7.5Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NetGIS allows Serialized Dat...
CVE-2026-7189HIGH7.5Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessin...
CVE-2026-16014HIGH7.3A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the compo...
CVE-2026-13410HIGH8.2Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled. The default user agent is in...
CVE-2026-13082MEDIUM5.3GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets. The random method creates the challenge ...
CVE-2026-16013MEDIUM5.5A vulnerability has been found in liftoff-sr CIPster up to 632336d414ef708a542377c1aa8d6fdb7c70a760. Affected by this is...
CVE-2026-16009MEDIUM6.3A vulnerability was detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file...
CVE-2026-15943MEDIUM5.5A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The is...
CVE-2026-9602MEDIUM6.5Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the D...
CVE-2026-8075MEDIUM6.5Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Matter...
CVE-2026-59695HIGH8.3Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the f...
CVE-2026-59694HIGH8.3Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the...
CVE-2026-59252HIGH8.2Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the f...
CVE-2026-16008MEDIUM6.3A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This impacts the function parseP...
CVE-2026-22104HIGH7.1Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows...
CVE-2026-62764MEDIUM6.5Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user...
CVE-2026-9656MEDIUM4.3The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information ...
CVE-2026-15380MEDIUM5.1A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — n...
CVE-2026-15379MEDIUM5.1The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents ...
CVE-2026-9810CRITICAL9.8The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any val...
CVE-2026-13402MEDIUM5.3The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the tem...
CVE-2026-12393MEDIUM5.4The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requ...
CVE-2026-11966MEDIUM5.3The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticate...
CVE-2026-11961HIGH8.1The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted d...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now