2026 CVE Vulnerabilities

57,114 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-12064HIGH7.5When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs betwe...
CVE-2026-11856CRITICAL9.8Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then ...
CVE-2026-11586HIGH7.5By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation...
CVE-2026-11564CRITICAL9.1libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches ...
CVE-2026-11352HIGH7.5An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service agai...
CVE-2026-10536CRITICAL9.8A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CU...
CVE-2026-9725CRITICAL9.1The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletio...
CVE-2026-9626MEDIUM6.4The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the p...
CVE-2026-9180MEDIUM5.3The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key...
CVE-2026-8892MEDIUM6.4The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2026-8489MEDIUM6.4The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2026-14352HIGH7.5The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8...
CVE-2026-13040HIGH7.2The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2026-12557MEDIUM5.3The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inc...
CVE-2026-11397MEDIUM5.5The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and in...
CVE-2026-8921HIGH8.5External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary co...
CVE-2026-12960MEDIUM6An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application o...
CVE-2026-14327HIGH7.5The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.4...
CVE-2026-12920MEDIUM4.9The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via ...
CVE-2026-12734MEDIUM6.4The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stor...
CVE-2026-12731MEDIUM6.4The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stor...
CVE-2026-12729MEDIUM4.3The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Miss...
CVE-2026-8247HIGH8.8An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local n...
CVE-2026-55726MEDIUM6.9The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious us...
CVE-2026-54477MEDIUM5.4The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now