2026 CVE Vulnerabilities

43,347 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-65451HIGH8.5Contributor SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-65450HIGH8.5Contributor SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-64814HIGH8.6In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
CVE-2026-64811HIGH7.8In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via develop...
CVE-2026-64809HIGH8.4In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configur...
CVE-2026-64808HIGH8.4In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tool...
CVE-2026-64807HIGH7.8In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
CVE-2026-64806HIGH8.4In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configur...
CVE-2026-64805HIGH8.4In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-loca...
CVE-2026-64804HIGH8.4In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-loca...
CVE-2026-64803HIGH7.8In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured...
CVE-2026-64802HIGH7.8In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules ...
CVE-2026-61954HIGH7.5Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.
CVE-2026-61947HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.
CVE-2026-61944HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.
CVE-2026-61943HIGH7.5Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.
CVE-2026-59554HIGH7.5Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.
CVE-2026-59547HIGH7.5Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.
CVE-2026-59545HIGH8.1Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
CVE-2026-59542HIGH7.7Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.
CVE-2026-59541HIGH8.8Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.
CVE-2026-59517HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.
CVE-2026-59512HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.
CVE-2026-57809HIGH7.1Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.
CVE-2026-57785HIGH8.8Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now