2026 CVE Vulnerabilities

59,349 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-12133MEDIUM4.3The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Missing Authori...
CVE-2026-12127MEDIUM5.3The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vu...
CVE-2026-12113MEDIUM4.3The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up...
CVE-2026-12110MEDIUM6.5The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to gene...
CVE-2026-12090MEDIUM6.5The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to gene...
CVE-2026-11988MEDIUM6.5The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure ...
CVE-2026-11981MEDIUM4.3The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.15.3 Thi...
CVE-2026-11380MEDIUM6.4The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and inc...
CVE-2026-20463MEDIUM6.7In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation o...
CVE-2026-20462MEDIUM6.7In Telephony, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation o...
CVE-2026-20461MEDIUM5.3In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of ser...
CVE-2026-20460MEDIUM5.3In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote informa...
CVE-2026-20459MEDIUM5.3In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service...
CVE-2026-20458HIGH7.5In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote escalation of p...
CVE-2026-20457MEDIUM5.3In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service...
CVE-2026-14191HIGH7.8An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeade...
CVE-2026-57963MEDIUM6.5An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, an...
CVE-2026-57962MEDIUM5.3A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitr...
CVE-2026-53488HIGH8.8containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plu...
CVE-2026-41579LOW3.3runc is a CLI tool for spawning and running containers according to the OCI specification. In versions prior to 1.3.6, 1...
CVE-2026-54903MEDIUM6.3Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.load ...
CVE-2026-54902MEDIUM6.3Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to version 3.17.2, is vulnerabl...
CVE-2026-54901MEDIUM6.3Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj::Pars...
CVE-2026-54900MEDIUM6.3Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, when in ...
CVE-2026-54899MEDIUM6.3Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to version 3.17.2, disabling sy...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now