2026 CVE Vulnerabilities

56,979 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15804HIGH8.8The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can inject SQL commands ...
CVE-2026-15583HIGH8.6A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's enviro...
CVE-2026-14251HIGH7.7A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when ...
CVE-2026-42936HIGH8.4The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory wh...
CVE-2026-12512HIGH8.6The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before us...
CVE-2026-12281HIGH8.1The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without ...
CVE-2026-11580MEDIUM5.5The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capab...
CVE-2026-11579MEDIUM5.3The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload ...
CVE-2026-8920HIGH8.5Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wa...
CVE-2026-8919HIGH7.2Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local us...
CVE-2026-15030MEDIUM5.6Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows ...
CVE-2026-15029HIGH8.4Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Mana...
CVE-2026-13585HIGH8.2Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in ...
CVE-2026-13385CRITICAL9.5An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows...
CVE-2026-11851MEDIUM5.9Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of ...
CVE-2026-9770MEDIUM5.3Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is s...
CVE-2026-13230MEDIUM6.5An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechan...
CVE-2026-5270CRITICAL9.8An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage...
CVE-2026-5269CRITICAL9.8In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used fo...
CVE-2026-51808CRITICAL9.8Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the open...
CVE-2026-51807CRITICAL9.8Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (...
CVE-2026-36035MEDIUM6.5Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Ser...
CVE-2026-15753MEDIUM5.4A vulnerability was determined in zhinianboke xianyu-auto-reply on Server. Affected by this vulnerability is an unknown ...
CVE-2026-15752HIGH7.3A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is a...
CVE-2026-15751MEDIUM5.3A security vulnerability has been detected in mastergo-design mastergo-magic-mcp up to 0.2.0. The affected element is th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now