2026 CVE Vulnerabilities

58,246 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-27060HIGH8.8Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember Premium allows Object Injection. This is...
CVE-2026-14449MEDIUM6.4u5CMS through v12.8.8 is vulnerable to reflected XSS via the ‘thanks’ parameter in multiple form components
CVE-2026-11946HIGH7.5An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The en...
CVE-2026-54431MEDIUM5.1In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header conta...
CVE-2026-54430MEDIUM5.1liboauth2 is vulnerable to Server-Side Request Forgery in oauth2_jose_jwks_aws_alb_resolve() function. The AWS ALB verif...
CVE-2026-9834HIGH7.2The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to OS Com...
CVE-2026-9188MEDIUM5.3The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Insecure Dire...
CVE-2026-9145MEDIUM6.5The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via ...
CVE-2026-8482MEDIUM4.3A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , ...
CVE-2026-8441HIGH7.5The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'notinstring' parameter of the wprp...
CVE-2026-14336HIGH8.2PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.o...
CVE-2026-14029MEDIUM6.5The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection ...
CVE-2026-13459MEDIUM5.3The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all versi...
CVE-2026-13369HIGH7.5The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the attach_files() function...
CVE-2026-13252MEDIUM6.4The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is...
CVE-2026-13251HIGH7.5The Perfmatters plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.4 vi...
CVE-2026-12657MEDIUM5.3The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direc...
CVE-2026-12472MEDIUM5.3The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypa...
CVE-2026-12134MEDIUM4.3The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to authorization b...
CVE-2026-12122MEDIUM5.3The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Sensitive Informat...
CVE-2026-11896MEDIUM5.3The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all...
CVE-2026-10104MEDIUM4.4The Product Video Gallery for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom_t...
CVE-2026-9563HIGH7.5In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default max...
CVE-2026-8147HIGH8.1In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper author...
CVE-2026-33592HIGH7.5An unauthenticated remote attacker can exhaust server memory via the FindServers Discovery Service in open62541. The ser...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now