2026 CVE Vulnerabilities

43,380 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-9713HIGH7.5The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table'...
CVE-2026-59678HIGH7.1An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary fi...
CVE-2026-12421HIGH7.2The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all version...
CVE-2026-14291HIGH7.5The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its ...
CVE-2026-12082HIGH7.5The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes...
CVE-2026-7534HIGH7.2The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST AP...
CVE-2026-7232HIGH7.2The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in ...
CVE-2026-64600HIGH7.8In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling I...
CVE-2026-15074HIGH7.5@fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the...
CVE-2026-16632HIGH7.3A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the lib...
CVE-2026-61246HIGH8.8Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...
CVE-2026-60455HIGH8.8Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...
CVE-2026-60439HIGH8.8Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...
CVE-2026-60373HIGH8.8Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...
CVE-2026-60371HIGH8Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...
CVE-2026-60370HIGH7.5Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...
CVE-2026-60368HIGH8.8Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...
CVE-2026-38766HIGH7.8An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_1...
CVE-2026-38765HIGH7.8An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kerne...
CVE-2026-64797HIGH7.5Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client...
CVE-2026-64792HIGH7.5Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extension...
CVE-2026-64791HIGH8.8Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager...
CVE-2026-63685HIGH8.8Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes and replacemen...
CVE-2026-63684HIGH8.8Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export ac...
CVE-2026-63683HIGH7.5Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now