2026 CVE Vulnerabilities

57,011 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-11964CRITICAL9.1The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity of incoming payment-p...
CVE-2026-11963HIGH8.1The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization check on a membershi...
CVE-2026-10551MEDIUM6.1The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to...
CVE-2026-15535MEDIUM6.3A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this is...
CVE-2026-15533MEDIUM4.7A security flaw has been discovered in DedeCMS 5.7.118. Impacted is an unknown function of the file /plus/search.php of ...
CVE-2026-15532LOW2.4A vulnerability was identified in SourceCodester Online Book Store System 1.0. This issue affects some unknown processin...
CVE-2026-15531MEDIUM5.3A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected ...
CVE-2026-15530MEDIUM5.5A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulnerability is the function config/listimage of the fi...
CVE-2026-9492HIGH8.5The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an ...
CVE-2026-7162HIGH7.8Successful exploitation of the integer overflow vulnerability could allow an attacker to achieve system-level access to ...
CVE-2026-15553MEDIUM6.9Enterprise Cloud Database developed by Ragic has a Arbitrary File Upload vulnerability, allowing unauthenticated remote ...
CVE-2026-15552MEDIUM6.1Enterprise Cloud Database developed by Ragic has a Stored Cross-Site Scripting vulnerability, allowing unauthenticated r...
CVE-2026-15529MEDIUM6.3A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the f...
CVE-2026-15528LOW3.3A vulnerability was found in lamaalrajih kicad-mcp up to 3.3.1. This issue affects some unknown processing of the file k...
CVE-2026-15527MEDIUM5.3A vulnerability has been found in better-auth better-icons up to 1.0.5. This vulnerability affects unknown code of the c...
CVE-2026-15526LOW3.3A flaw has been found in augmnt augments-mcp-server 7.1.0. This issue affects the function scanProjectDeps of the file s...
CVE-2026-15525MEDIUM6.3A vulnerability was detected in kLOsk adloop up to 0.9.0. This vulnerability affects the function _validate_urls of the ...
CVE-2026-15524LOW3.3A security vulnerability has been detected in alioshr memory-bank-mcp up to 0.2.1/3.1. This affects an unknown part of t...
CVE-2026-15523MEDIUM6.3A weakness has been identified in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some un...
CVE-2026-15522MEDIUM5.3A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0. Affected by this vulnerability is the function v...
CVE-2026-15521MEDIUM5.3A vulnerability was identified in makafeli n8n-workflow-builder up to 0.11.0. Affected is an unknown function of the fil...
CVE-2026-15520MEDIUM5.3A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035. This impacts the function decompress_R2004_section ...
CVE-2026-15519MEDIUM5A vulnerability was found in usestrix strix up to 1.0.2. This affects an unknown function of the file system_prompt.jinj...
CVE-2026-15551MEDIUM5.5Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects...
CVE-2026-15518MEDIUM4.7A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. The impacted element is the function FileLibraryControl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now