2026 CVE Vulnerabilities

44,067 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-12205CRITICAL9.1Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DS...
CVE-2026-48714CRITICAL9.1i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno...
CVE-2026-48713CRITICAL9.1Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missi...
CVE-2026-12087CRITICAL9.1Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the l...
CVE-2026-11832CRITICAL9.1Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was genera...
CVE-2026-9691CRITICAL9.8Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja For...
CVE-2026-52703CRITICAL9.6Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.
CVE-2026-52693CRITICAL9.3Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions.
CVE-2026-49781CRITICAL9.8Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.
CVE-2026-49776CRITICAL9.3Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websit...
CVE-2026-49770CRITICAL9.8Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.
CVE-2026-49769CRITICAL9.8Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions.
CVE-2026-49768CRITICAL9.8Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.
CVE-2026-49766CRITICAL9.9Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.
CVE-2026-49765CRITICAL9.8Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <=...
CVE-2026-49764CRITICAL9.8Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.
CVE-2026-49763CRITICAL9.8Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.
CVE-2026-49109CRITICAL9.8Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, N...
CVE-2026-49106CRITICAL9.8Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions.
CVE-2026-49105CRITICAL9.8Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <=...
CVE-2026-49104CRITICAL9.8Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formid...
CVE-2026-49085CRITICAL9.8Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms ...
CVE-2026-49067CRITICAL9.3Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.
CVE-2026-48886CRITICAL9.3Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions.
CVE-2026-48881CRITICAL9.1Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now