2026 CVE Vulnerabilities

59,953 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8095HIGH8.1The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions...
CVE-2026-10643HIGH7.8Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user...
CVE-2026-49416HIGH7.8The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer ...
CVE-2026-49414HIGH7.8The ELF image activator cleared per-process ASLR preference flags for setuid binaries after the code that computes the P...
CVE-2026-49417HIGH7Second, the audio buffer backing a mapping could be freed when the device was closed even though the mapping remained va...
CVE-2026-49413HIGH7.1The Linuxulator determined whether a binary was set-user-ID or set-group-ID by checking the P_SUGID process flag. Durin...
CVE-2026-49412HIGH7.8The kernel handler for IPV6_MSFILTER dropped a serializing lock in order to copy the source-filter list from userspace, ...
CVE-2026-45259MEDIUM6.5sigqueue(2) was marked as permitted in capability mode with the introduction of Capsicum in 2011, but the implementation...
CVE-2026-45258HIGH7.8dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the...
CVE-2026-9242MEDIUM5.3The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu...
CVE-2026-9233MEDIUM4.3The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass...
CVE-2026-3462MEDIUM6.5The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks...
CVE-2026-13295MEDIUM6.4The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via panels_data Paramet...
CVE-2026-12471MEDIUM4.3The Spexo theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the activate_plu...
CVE-2026-12432MEDIUM5.3The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8....
CVE-2026-12399MEDIUM4.4The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2026-11987MEDIUM4.3The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPr...
CVE-2026-11783MEDIUM6.4The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPr...
CVE-2026-11773MEDIUM4.3The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypas...
CVE-2026-11597MEDIUM6.4The Surbma | Infusionsoft Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'infusions...
CVE-2026-11364MEDIUM4.3The Product Specifications for WooCommerce plugin for WordPress is vulnerable to unauthorized modification, creation, an...
CVE-2026-9677MEDIUM4.8The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_infourl se...
CVE-2026-13245MEDIUM6.1The MaxButtons – Create buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'view' para...
CVE-2026-12404MEDIUM5.3The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all ve...
CVE-2026-10820HIGH8.1The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now