2026 CVE Vulnerabilities

57,111 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-11778MEDIUM5.4The The CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x plugin for WordPress is vulnerable to arbit...
CVE-2026-11398MEDIUM5.3The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to authorization ...
CVE-2026-9230MEDIUM4.3The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass...
CVE-2026-9148HIGH7.2The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Websi...
CVE-2026-8804MEDIUM6.7Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensiti...
CVE-2026-8351MEDIUM6.4The RTMKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget's 'Backgrou...
CVE-2026-47898CRITICAL9.8Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common lib...
CVE-2026-47897HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucen...
CVE-2026-14544CRITICAL9.8A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8...
CVE-2026-9547HIGH7.4When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION`...
CVE-2026-9546HIGH7.5A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the document...
CVE-2026-9545HIGH7.5In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transf...
CVE-2026-9080HIGH7.3Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerab...
CVE-2026-9079CRITICAL9.8libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the o...
CVE-2026-8932HIGH7.5libcurl would reuse a previously created connection even when some mTLS config related option had been changed that shou...
CVE-2026-8927CRITICAL9.1When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails...
CVE-2026-8926CRITICAL9.1When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(withou...
CVE-2026-8925CRITICAL9.8The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing t...
CVE-2026-8924CRITICAL9.1A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffi...
CVE-2026-8458MEDIUM6.5libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when ...
CVE-2026-8286HIGH8.1A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live co...
CVE-2026-4967HIGH7.5In IMS, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of servic...
CVE-2026-12064HIGH7.5When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs betwe...
CVE-2026-11856CRITICAL9.8Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then ...
CVE-2026-11586HIGH7.5By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now