2026 CVE Vulnerabilities

43,896 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-19266MEDIUM5.5A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the f...
CVE-2026-19263HIGH7.3A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114. The impacted elem...
CVE-2026-19259MEDIUM5.3A vulnerability has been found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function MmsMapping...
CVE-2026-16955MEDIUM5The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwardi...
CVE-2026-16953MEDIUM4.8The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deleti...
CVE-2026-16948HIGH8.1The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exp...
CVE-2026-16608MEDIUM5.3The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging ...
CVE-2026-16595MEDIUM6.5The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti...
CVE-2026-16594HIGH7.5The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti...
CVE-2026-16590MEDIUM6.5The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti...
CVE-2026-16589HIGH7.7The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL sta...
CVE-2026-16578HIGH7.5The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does n...
CVE-2026-16574MEDIUM5.4The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that ...
CVE-2026-16562MEDIUM6.5The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics ...
CVE-2026-16559MEDIUM6.8The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload featur...
CVE-2026-16558MEDIUM5.4The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it...
CVE-2026-16535MEDIUM6.1The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a r...
CVE-2026-16282MEDIUM5.3The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against t...
CVE-2026-16269MEDIUM4.8The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthentica...
CVE-2026-16267HIGH8.1The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from...
CVE-2026-14526CRITICAL9.8The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and...
CVE-2026-18988MEDIUM6.4The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block a...
CVE-2026-13505HIGH8.7In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X ser...
CVE-2026-8798HIGH8.7In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried ...
CVE-2026-52880HIGH7.5Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now