2026 CVE Vulnerabilities

57,068 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5356HIGH7.5The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input...
CVE-2026-14454CRITICAL9.8Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD ...
CVE-2026-12002MEDIUM4.7The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request ...
CVE-2026-6854HIGH7.5The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the ...
CVE-2026-6818HIGH7.2The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'spe...
CVE-2026-6742MEDIUM6.4The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in ...
CVE-2026-6371MEDIUM4.8Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Limatek System Inc...
CVE-2026-6230HIGH7.5The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all ve...
CVE-2026-41042CRITICAL9.1Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java...
CVE-2026-3688HIGH8.1The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure...
CVE-2026-14250MEDIUM6.3The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and inclu...
CVE-2026-12936MEDIUM4.9The Recurio – Ultimate Subscription for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the ...
CVE-2026-15041LOW3.7A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for co...
CVE-2026-56003HIGH8.8A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeSc...
CVE-2026-56002HIGH8.8A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers auth...
CVE-2026-6280MEDIUM6.5Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consu...
CVE-2026-57260HIGH7.8The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly re...
CVE-2026-57259MEDIUM6.5The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, th...
CVE-2026-57258MEDIUM6.1The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underl...
CVE-2026-57257MEDIUM6.1During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-o...
CVE-2026-57256HIGH7.8When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and thi...
CVE-2026-57255MEDIUM6.1The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malfo...
CVE-2026-57254HIGH7.8There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF,...
CVE-2026-57253MEDIUM6.1An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an in...
CVE-2026-57252HIGH7.8When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotatio...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now