2026 CVE Vulnerabilities

57,996 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8927CRITICAL9.1When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails...
CVE-2026-8926CRITICAL9.1When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (witho...
CVE-2026-8925CRITICAL9.8The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing t...
CVE-2026-8924CRITICAL9.1A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public Suffi...
CVE-2026-8458MEDIUM6.5libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when ...
CVE-2026-8286HIGH8.1A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live co...
CVE-2026-4967HIGH7.5In IMS, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of servic...
CVE-2026-12064HIGH7.5When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs betwe...
CVE-2026-11856CRITICAL9.8Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then ...
CVE-2026-11586HIGH7.5By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation...
CVE-2026-11564CRITICAL9.1libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches ...
CVE-2026-11352HIGH7.5An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service agai...
CVE-2026-10536CRITICAL9.8A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CU...
CVE-2026-9725CRITICAL9.1The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletio...
CVE-2026-9626MEDIUM6.4The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the p...
CVE-2026-9180MEDIUM5.3The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key...
CVE-2026-8892MEDIUM6.4The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2026-8489MEDIUM6.4The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2026-14352HIGH7.5The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8...
CVE-2026-13040HIGH7.2The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2026-12557MEDIUM5.3The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inc...
CVE-2026-11397MEDIUM5.5The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and in...
CVE-2026-8921HIGH8.5External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary co...
CVE-2026-12960MEDIUM6An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application o...
CVE-2026-14327HIGH7.5The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.4...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now