2026 CVE Vulnerabilities

59,863 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8141HIGH7.2The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include...
CVE-2026-6954MEDIUM5.1Cross-Site Scripting (XSS) vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to...
CVE-2026-6953MEDIUM5.1HTML injection vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to send an ema...
CVE-2026-13149HIGH7.7brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time comple...
CVE-2026-12610MEDIUM6.4A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free v...
CVE-2026-12076CRITICAL9.3Raytha CMS is vulnerable to SQL Injection within the OData filter parsing pipeline.  The vulnerability allows a remote, ...
CVE-2026-10763HIGH7PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support fr...
CVE-2026-45822MEDIUM6.6decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' produci...
CVE-2026-12578HIGH8.4The affected product is vulnerable to a deserialization of untrusted data, which may allow an attacker to execute arbitr...
CVE-2026-9576MEDIUM4.9The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting a...
CVE-2026-56809MEDIUM5.1Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cr...
CVE-2026-56808HIGH8.6DGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which may lead to arb...
CVE-2026-56137HIGH8.4RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads ...
CVE-2026-14164HIGH7.5A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive,...
CVE-2026-12819CRITICAL9.3Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access contro...
CVE-2026-12818CRITICAL9.3Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-...
CVE-2026-12240HIGH8The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat...
CVE-2026-11590HIGH8.6The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sanitize user-supplied array keys b...
CVE-2026-11589HIGH8.8The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not properly validate uploaded files, a...
CVE-2026-11581MEDIUM5.9The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's ca...
CVE-2026-8944MEDIUM4.3The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in v...
CVE-2026-12560MEDIUM4.4The Editorial Rating – Product Review & Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2026-12349MEDIUM5.3The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in ...
CVE-2026-12073CRITICAL9.8The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via a...
CVE-2026-11367MEDIUM6.5The PixMagix – WordPress Image Editor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now