2026 CVE Vulnerabilities

57,119 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-53357HIGH8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() v...
CVE-2026-50748CRITICAL9.9A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability...
CVE-2026-50747CRITICAL9.9A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vu...
CVE-2026-50746CRITICAL10A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Conne...
CVE-2026-12168HIGH7.8An improper validation vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to escal...
CVE-2026-12167HIGH7.8The Minifilter communication port for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to access p...
CVE-2026-12166MEDIUM5.5A NULL pointer dereference vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to c...
CVE-2026-4767CRITICAL9.8Missing authentication for critical function vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Authentication Abu...
CVE-2026-5524CRITICAL9.8The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in al...
CVE-2026-58653MEDIUM5.3PraisonAI before 0.1.7 fails to validate that project_id in issue create and update request bodies belongs to the URL wo...
CVE-2026-58652HIGH7.5luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the lu...
CVE-2026-4772MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defens...
CVE-2026-4770MEDIUM4.6Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defens...
CVE-2026-57766HIGH8.8Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions.
CVE-2026-57765HIGH8.5Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.
CVE-2026-57764MEDIUM6.5Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions.
CVE-2026-57763MEDIUM6.5Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions.
CVE-2026-57762MEDIUM5.9Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions.
CVE-2026-57761HIGH7.1Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions.
CVE-2026-57760MEDIUM5.3Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Cont...
CVE-2026-57759HIGH8.8Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions.
CVE-2026-57758HIGH7.1Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions.
CVE-2026-57757HIGH7.1Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions.
CVE-2026-57756HIGH8.5Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions.
CVE-2026-57755MEDIUM6.5Contributor Cross Site Scripting (XSS) in Mosaic Gallery &#8211; Advanced Gallery <= 1.2.0 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now