2026 CVE Vulnerabilities

43,311 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-8789HIGH8.1The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2026-55732HIGH8.7Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-R...
CVE-2026-55730HIGH8.7Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenti...
CVE-2026-55729HIGH7.7Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all pla...
CVE-2026-16801HIGH8.8Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2...
CVE-2026-16800HIGH8.8Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 20...
CVE-2026-12504HIGH8.4Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-...
CVE-2026-12502HIGH8.4Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, ...
CVE-2026-12496HIGH8.7Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-I...
CVE-2026-9765HIGH7.1Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are ...
CVE-2026-66144HIGH7.5Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the ...
CVE-2026-66143HIGH7.5It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2...
CVE-2026-66142HIGH7.5Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested s...
CVE-2026-45816HIGH7.5NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asser...
CVE-2026-45815HIGH7.5Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_...
CVE-2026-45813HIGH8.8Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper valida...
CVE-2026-45811HIGH7.5Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket tr...
CVE-2026-15810HIGH8.7A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.6...
CVE-2026-15243HIGH7.4Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches th...
CVE-2026-10610HIGH8.5Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user.
CVE-2026-7483HIGH8.5Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a...
CVE-2026-15401HIGH7.2The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbf...
CVE-2026-10033HIGH7.3The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including,...
CVE-2026-49745HIGH7.8Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ...
CVE-2026-49744HIGH7.8Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now