2026 CVE Vulnerabilities

58,073 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-9079CRITICAL9.8libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the o...
CVE-2026-8932HIGH7.5libcurl would reuse a previously created connection even when some mTLS config related option had been changed that shou...
CVE-2026-8927CRITICAL9.1When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails...
CVE-2026-8926CRITICAL9.1When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (witho...
CVE-2026-8925CRITICAL9.8The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing t...
CVE-2026-8924CRITICAL9.1A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public Suffi...
CVE-2026-8458MEDIUM6.5libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when ...
CVE-2026-8286HIGH8.1A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live co...
CVE-2026-4967HIGH7.5In IMS, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of servic...
CVE-2026-12064HIGH7.5When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs betwe...
CVE-2026-11856CRITICAL9.8Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then ...
CVE-2026-11586HIGH7.5By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation...
CVE-2026-11564CRITICAL9.1libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches ...
CVE-2026-11352HIGH7.5An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service agai...
CVE-2026-10536CRITICAL9.8A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CU...
CVE-2026-9725CRITICAL9.1The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletio...
CVE-2026-9626MEDIUM6.4The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the p...
CVE-2026-9180MEDIUM5.3The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key...
CVE-2026-8892MEDIUM6.4The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2026-8489MEDIUM6.4The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2026-14352HIGH7.5The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8...
CVE-2026-13040HIGH7.2The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2026-12557MEDIUM5.3The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inc...
CVE-2026-11397MEDIUM5.5The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and in...
CVE-2026-8921HIGH8.5External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary co...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now