2026 CVE Vulnerabilities

59,953 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-12415CRITICAL9.8The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on th...
CVE-2026-13422MEDIUM4.3The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to ...
CVE-2026-13335MEDIUM6.4The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cpm_point...
CVE-2026-13333MEDIUM6.5The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection ...
CVE-2026-13331MEDIUM6.5The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection ...
CVE-2026-11356MEDIUM4.4The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'menu_t...
CVE-2026-56414HIGH8.6A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arb...
CVE-2026-55975HIGH8.6A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fields to t...
CVE-2026-33560HIGH8.8The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which a...
CVE-2026-31928CRITICAL9.8The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are ...
CVE-2026-28701MEDIUM5.3Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape ...
CVE-2026-55069HIGH8.7Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAu...
CVE-2026-53577MEDIUM6.5Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the previewFileFromExecution ...
CVE-2026-53576CRITICAL10Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for...
CVE-2026-50767MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System...
CVE-2026-50766MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 throu...
CVE-2026-50765MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Man...
CVE-2026-49984HIGH7.7Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage ba...
CVE-2026-49869CRITICAL10Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestr...
CVE-2026-45807HIGH7.7Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.43 and 1.3.19, several Kestra API endpoints ...
CVE-2026-38571MEDIUM4.6Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands, ...
CVE-2026-36908MEDIUM5.5A stack overflow in the AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity component of axiomatic-systems Bento4 before v1.8...
CVE-2026-36907MEDIUM5.5A stack overflow in the AP4_StsdAtom::AP4_StsdAtom component of axiomatic-systems Bento4 before v1.8.9allows attackers t...
CVE-2026-36478HIGH7.5An issue in Technitium DNS Server v.14.3 and before allows a remote attacker to cause a denial of service via the DnsSer...
CVE-2026-54353HIGH7.1Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypas...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now