2026 CVE Vulnerabilities

43,347 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-14257HIGH7.5brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the...
CVE-2026-65908HIGH8.6In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on un...
CVE-2026-65897HIGH8.8Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing au...
CVE-2026-65896HIGH7.1Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in th...
CVE-2026-65895HIGH8.5Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, a...
CVE-2026-65608HIGH8.8Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField()...
CVE-2026-65607HIGH7.1SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit branch of the serveExpor...
CVE-2026-65540HIGH7.1Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.
CVE-2026-65539HIGH7.1Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.
CVE-2026-65532HIGH7.6Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.
CVE-2026-65526HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualiz...
CVE-2026-65516HIGH7.2Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.
CVE-2026-65511HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5....
CVE-2026-65510HIGH7.1Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.
CVE-2026-65500HIGH7.5Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 ver...
CVE-2026-65497HIGH7.2Administrator PHP Object Injection in Complianz <= 7.5.0 versions.
CVE-2026-65495HIGH7.5Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.
CVE-2026-65494HIGH7.1Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.
CVE-2026-65493HIGH7.5Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.
CVE-2026-65492HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versions.
CVE-2026-65488HIGH7.1Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
CVE-2026-65481HIGH7.5Contributor Local File Inclusion in Vino <= 1.9 versions.
CVE-2026-65477HIGH7.5Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.
CVE-2026-65462HIGH7.6Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.
CVE-2026-65454HIGH8.5Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now