2026 CVE Vulnerabilities

56,354 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-24428HIGH8.8Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain an authorization flaw in the user...
CVE-2026-21509HIGH7.8Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a secu...
CVE-2026-1284HIGH7.8An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLI...
CVE-2026-1283HIGH7.8A Heap-based Buffer Overflow vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Releas...
CVE-2026-1428HIGH8.8Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated re...
CVE-2026-1427HIGH8.8Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated re...
CVE-2026-1424HIGH7.2A vulnerability was identified in PHPGurukul News Portal 1.0. This affects an unknown part of the component Profile Pic ...
CVE-2026-1419HIGH7.2A weakness has been identified in D-Link DCS700l 1.03.09. Affected is an unknown function of the file /setDayNightMode o...
CVE-2026-1418HIGH7.8A security vulnerability has been detected in GPAC up to 2.4.0. This affects the function gf_text_import_srt_bifs of the...
CVE-2026-23013HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: octeon_ep_vf: fix free_irq dev_id mismatch in ...
CVE-2026-23012HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: remove call_control in inactive cont...
CVE-2026-23010HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix use-after-free in inet6_addr_del(). syzb...
CVE-2026-23001HIGH7.8In the Linux kernel, the following vulnerability has been resolved: macvlan: fix possible UAF in macvlan_forward_source...
CVE-2026-22998HIGH7.5In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix NULL pointer dereferences in nvmet_tc...
CVE-2026-0911HIGH7.5The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to arbitrary file uploa...
CVE-2026-0800HIGH7.2The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored ...
CVE-2026-1257HIGH7.5The Administrative Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and incl...
CVE-2026-0807HIGH7.2The Frontis Blocks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin...
CVE-2026-24469HIGH7.5C++ HTTP Server is an HTTP/1.1 server built to handle client connections and serve HTTP requests. Versions 1.0 and below...
CVE-2026-24422HIGH7.5phpMyFAQ is an open source FAQ web application. In versions 4.0.16 and below, multiple public API endpoints improperly e...
CVE-2026-24412HIGH8.8iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers...
CVE-2026-24411HIGH8.8iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers...
CVE-2026-24410HIGH8.8iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers...
CVE-2026-24409HIGH8.8iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers...
CVE-2026-24407HIGH8.8iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now