2026 CVE Vulnerabilities

57,996 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-10055HIGH8.5In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from...
CVE-2026-10054HIGH8.8In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSoc...
CVE-2026-5137MEDIUM4.3The RTMKit (rometheme-for-elementor) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and i...
CVE-2026-4322MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Raera - Ankara Web...
CVE-2026-4321CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web...
CVE-2026-9756MEDIUM6.4The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldTy...
CVE-2026-4804MEDIUM6.4The Zakra theme for WordPress is vulnerable to Stored Cross-Site Scripting via post meta values in all versions up to, a...
CVE-2026-47896HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucen...
CVE-2026-35159MEDIUM5.3Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attack...
CVE-2026-11900MEDIUM4.3The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Insecure Direct Object Reference in ver...
CVE-2026-11778MEDIUM5.4The The CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x plugin for WordPress is vulnerable to arbit...
CVE-2026-11398MEDIUM5.3The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to authorization ...
CVE-2026-9230MEDIUM4.3The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass...
CVE-2026-9148HIGH7.2The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Websi...
CVE-2026-8804MEDIUM6.7Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensiti...
CVE-2026-8351MEDIUM6.4The RTMKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget's 'Backgrou...
CVE-2026-47898CRITICAL9.8Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common lib...
CVE-2026-47897HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucen...
CVE-2026-14544CRITICAL9.8A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8...
CVE-2026-9547HIGH7.4When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION`...
CVE-2026-9546HIGH7.5A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the document...
CVE-2026-9545HIGH7.5In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transf...
CVE-2026-9080HIGH7.3Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerab...
CVE-2026-9079CRITICAL9.8libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the o...
CVE-2026-8932HIGH7.5libcurl would reuse a previously created connection even when some mTLS config related option had been changed that shou...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now