2026 CVE Vulnerabilities

57,056 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-12879MEDIUM5.9An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google...
CVE-2026-12593HIGH8.7The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to en...
CVE-2026-12116CRITICAL9.8A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings,...
CVE-2026-15184LOW3.3A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted element is the function dwg_next_entity of the file...
CVE-2026-9253HIGH7.2The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scrip...
CVE-2026-15182MEDIUM5.3A vulnerability has been found in GNU LibreDWG up to 0.13.4. The affected element is the function dwg_bmp of the file sr...
CVE-2026-9240MEDIUM4.3The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress is vulnerable to unauthorized modif...
CVE-2026-9237MEDIUM4.3The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization byp...
CVE-2026-9235MEDIUM4.3The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of ...
CVE-2026-9028MEDIUM5.3The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up ...
CVE-2026-9027MEDIUM5.3The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification...
CVE-2026-9021MEDIUM5.3The Easy Invoice plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.19. T...
CVE-2026-59692HIGH7.5A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificat...
CVE-2026-59691HIGH7.1A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/V...
CVE-2026-58307MEDIUM6.1Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Dat...
CVE-2026-58306MEDIUM6.1Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Es...
CVE-2026-58305MEDIUM6.1Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Point...
CVE-2026-58304MEDIUM6.1Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This iss...
CVE-2026-58303MEDIUM6.1Stack-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects E...
CVE-2026-56291CRITICAL9.8Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension B...
CVE-2026-56289MEDIUM5.5GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff...
CVE-2026-56288MEDIUM5.5GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Impro...
CVE-2026-50644HIGH8.6SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all right...
CVE-2026-4298MEDIUM4.3The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and includ...
CVE-2026-4275HIGH8.8The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request F...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now