2026 CVE Vulnerabilities

56,359 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-21524HIGH7.4Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to dis...
CVE-2026-21521HIGH7.4Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose inf...
CVE-2026-21520HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view s...
CVE-2026-23988HIGH7Rufus is a utility that helps format and create bootable USB flash drives. Versions 4.11 and below contain a race condit...
CVE-2026-23954HIGH8.7Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to laun...
CVE-2026-23953HIGH8.7Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch...
CVE-2026-20736HIGH7.5Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachmen...
CVE-2026-22279HIGH7.5Dell PowerScale OneFS, versions prior 9.13.0.0, contains an insufficient logging vulnerability. An unauthenticated attac...
CVE-2026-24390HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-24367HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Travele...
CVE-2026-23978HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-23975HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-23763HIGH8.5VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a local p...
CVE-2026-22470HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FireStorm Plugins ...
CVE-2026-22464HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-22402HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-22401HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-22355HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in gregmolnar Simple XML Sitemap simple-xml-sitemap allows Stored XSS.Th...
CVE-2026-1260HIGH7.8Invalid memory access in Sentencepiece versions less than 0.2.1 when using a vulnerable model file, which is not created...
CVE-2026-0535HIGH8.1A maliciously crafted HTML payload, stored in a component’s description and clicked by a user, can trigger a Stored Cros...
CVE-2026-0534HIGH8.1A maliciously crafted HTML payload, stored in a part’s attribute and clicked by a user, can trigger a Stored Cross-site ...
CVE-2026-0533HIGH8.1A maliciously crafted HTML payload in a design name, when displayed during the delete confirmation dialog and clicked by...
CVE-2026-1329HIGH8.8A flaw has been found in Tenda AX1803 1.0.0.1. The affected element is the function fromGetWifiGuestBasic of the file /g...
CVE-2026-1328HIGH8.8A vulnerability was detected in Totolink NR1800X 9.1.0u.6279_B20210910. Impacted is the function setWizardCfg of the fil...
CVE-2026-1327HIGH8.8A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function se...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now