2026 CVE Vulnerabilities

57,056 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-14372HIGH7.1The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is v...
CVE-2026-13441HIGH7.2The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2026-12590MEDIUM5.9Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an i...
CVE-2026-12428MEDIUM6.5The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ...
CVE-2026-5955CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software an...
CVE-2026-5793MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Inrove Software an...
CVE-2026-56460MEDIUM6.5HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API respons...
CVE-2026-56459MEDIUM5.5HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure.  The application stores potentially s...
CVE-2026-56458HIGH7.5HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged action...
CVE-2026-2342CRITICAL9.3Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Inform...
CVE-2026-1989HIGH7.5Authorization bypass through User-Controlled key vulnerability in PAVO Financial Technology Solutions Inc. PAVO Pay allo...
CVE-2026-1365MEDIUM6.5Insertion of sensitive information into sent data vulnerability in Sayax Energy Technologies Inc. OSOS allows Authentica...
CVE-2026-15158CRITICAL9.8The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, ...
CVE-2026-12433MEDIUM4.3The Hydra Booking – Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Obje...
CVE-2026-8996MEDIUM6.5The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve...
CVE-2026-8848HIGH7.2The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress ...
CVE-2026-7558MEDIUM5.3The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to unauthorized access...
CVE-2026-6910MEDIUM6.4The Bookero.pl – system rezerwacji online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `boo...
CVE-2026-59269LOW3.8A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permissions in ...
CVE-2026-57111HIGH7.5Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFi...
CVE-2026-4653MEDIUM6.4The Block, Suspend, Report for BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lin...
CVE-2026-33390HIGH8.1An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors r...
CVE-2026-31985HIGH8.3When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disab...
CVE-2026-31984HIGH8.7A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functional...
CVE-2026-31983MEDIUM6.9A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attac...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now