2026 CVE Vulnerabilities

42,999 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-73431HIGH8.8Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Ac...
CVE-2026-73291HIGH7.1Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr'...
CVE-2026-73289HIGH8.1RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: ...
CVE-2026-73286HIGH8.1RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds a...
CVE-2026-73285HIGH7.5RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA a...
CVE-2026-73284HIGH8.8RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/servi...
CVE-2026-73264HIGH7.6Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration acce...
CVE-2026-68757HIGH7.5A user with access to a valid SAML response may impersonate another user under specific conditions.
CVE-2026-68752HIGH7.2A Project Resource Manager may gain broader administrative privileges under specific conditions.
CVE-2026-66375HIGH8.1A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific...
CVE-2026-14478HIGH7.8A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to in...
CVE-2026-47231HIGH8.1Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-c...
CVE-2026-70468HIGH8.1A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7....
CVE-2026-57858HIGH8.9Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagMa...
CVE-2026-53996HIGH7NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unpr...
CVE-2026-70465HIGH8.1A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7....
CVE-2026-11325HIGH8.8Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, ...
CVE-2026-19426HIGH8.8POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directl...
CVE-2026-19594HIGH8.1Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-dep...
CVE-2026-18789HIGH7.5The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, ...
CVE-2026-18474HIGH8.6The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL sta...
CVE-2026-64954HIGH8.2Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, th...
CVE-2026-12234HIGH7.8The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c sn...
CVE-2026-18961HIGH8.1The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnera...
CVE-2026-73122HIGH7.7A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vuln...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now