2026 CVE Vulnerabilities

44,056 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-14943HIGH7.5The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 d...
CVE-2026-14331MEDIUM6.1The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a...
CVE-2026-14205CRITICAL9.8The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid...
CVE-2026-49005LOW2.4The root password hash of the device can be obtained through unencrypted information in the firmware.
CVE-2026-19195HIGH7.8A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in th...
CVE-2026-19193HIGH7.8A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys...
CVE-2026-19192HIGH7.8A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C...
CVE-2026-19191HIGH7.8A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code o...
CVE-2026-14365CRITICAL9.8The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in ...
CVE-2026-14364CRITICAL9.8The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via imp...
CVE-2026-12801MEDIUM6.4The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Range Slid...
CVE-2026-11907MEDIUM6.5The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This ...
CVE-2026-19190HIGH7.8A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Fil...
CVE-2026-49746HIGH7.1Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memor...
CVE-2026-45204MEDIUM5.5Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger OOB access and kern...
CVE-2026-45198HIGH7.8Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause G...
CVE-2026-19189HIGH7.8A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functional...
CVE-2026-70332CRITICAL9.6Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-68823CRITICAL9.1Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a n...
CVE-2026-65668HIGH8.8Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a netwo...
CVE-2026-65667CRITICAL10Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-63508CRITICAL10Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elev...
CVE-2026-62918HIGH7.5Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing ...
CVE-2026-62896CRITICAL9.6Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
CVE-2026-62873CRITICAL9.8Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now