2026 CVE Vulnerabilities

43,347 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-66143HIGH7.5It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2...
CVE-2026-66142HIGH7.5Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested s...
CVE-2026-45816HIGH7.5NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asser...
CVE-2026-45815HIGH7.5Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_...
CVE-2026-45813HIGH8.8Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper valida...
CVE-2026-45811HIGH7.5Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket tr...
CVE-2026-15810HIGH8.7A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.6...
CVE-2026-15243HIGH7.4Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches th...
CVE-2026-10610HIGH8.5Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user.
CVE-2026-7483HIGH8.5Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a...
CVE-2026-15401HIGH7.2The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbf...
CVE-2026-10033HIGH7.3The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including,...
CVE-2026-49745HIGH7.8Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ...
CVE-2026-49744HIGH7.8Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ...
CVE-2026-49743HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of...
CVE-2026-16519HIGH7.3A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads on...
CVE-2026-14603HIGH7.5The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint...
CVE-2026-14172HIGH7.8Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without ...
CVE-2026-12981HIGH7.5The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user pas...
CVE-2026-12497HIGH7.5The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl...
CVE-2026-16870HIGH8.8Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execut...
CVE-2026-66141HIGH7.4Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
CVE-2026-66140HIGH8.4Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privilege...
CVE-2026-66138HIGH7.2In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code ...
CVE-2026-12736HIGH8The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now