2026 CVE Vulnerabilities

57,035 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41876HIGH8.7R-SOFT DMS is vulnerable to OS Command Injection in konwertujAction() function. The document converter executes shell co...
CVE-2026-15378CRITICAL9.3A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind...
CVE-2026-15028LOW3.9A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a sp...
CVE-2026-13710MEDIUM6.4The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vul...
CVE-2026-13247MEDIUM6.4The Logo Slider – Logo Carousel, Client Logo Slider & Brand Showcase for WordPress plugin for WordPress is vulnerable to...
CVE-2026-13010MEDIUM6.5The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL ...
CVE-2026-12918MEDIUM4.9The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to...
CVE-2026-11990MEDIUM5.3The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in al...
CVE-2026-9838MEDIUM6.1The ICS Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'htmltagtitle' parameter i...
CVE-2026-6802MEDIUM5.3The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, a...
CVE-2026-6440MEDIUM4.3The GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference plugin for WordPress is vulnerable to Cro...
CVE-2026-3907MEDIUM6.4The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wphostel-book' shortcode in all ve...
CVE-2026-1946MEDIUM4.3The GW AI Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab...
CVE-2026-15104MEDIUM6.5The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to g...
CVE-2026-15026MEDIUM4.3The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve...
CVE-2026-14475MEDIUM4.9The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via ...
CVE-2026-12955MEDIUM4.3The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil...
CVE-2026-12924MEDIUM6.4The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to S...
CVE-2026-12400MEDIUM4.3The FlowForms – Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in al...
CVE-2026-12108MEDIUM4.4The Highlighting Code Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ...
CVE-2026-11992MEDIUM4.3The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3...
CVE-2026-40454HIGH7.5Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. Out-of-bounds reads in IoTDB C++...
CVE-2026-40452HIGH7.5Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLas...
CVE-2026-40009MEDIUM6.5Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated users can escalate t...
CVE-2026-40008CRITICAL9.8Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoTDB. The pi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now