2026 CVE Vulnerabilities

64,751 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-97527HIGH8.8In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Serialize NVMe unsol ctx list with a...
CVE-2026-97525HIGH8.2In the Linux kernel, the following vulnerability has been resolved: x86/mm/pat: Allocate split page tables as kernel pa...
CVE-2026-97524HIGH7.5In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid unneeded actions on subflow reset Onc...
CVE-2026-97523HIGH7.5In the Linux kernel, the following vulnerability has been resolved: mptcp: close race between scheduler and state chang...
CVE-2026-97898HIGH8.4Insecure Direct Object Reference / missing object-level authorization in the Akia keyless entry cloud service. The unloc...
CVE-2026-92560HIGH7.5A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential...
CVE-2026-92550HIGH7.5A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential...
CVE-2026-96752HIGH7.2The Zero Spam for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Nested POST Array Keys...
CVE-2026-96568HIGH7.2The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_n...
CVE-2026-95866HIGH7.2The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v...
CVE-2026-95864HIGH7.2The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'css[fonts]' Parameter in all ...
CVE-2026-94573HIGH7.2The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater F...
CVE-2026-93901HIGH7.3The Optima Express IDX plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, ...
CVE-2026-93654HIGH7.2The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2026-92713HIGH8.1The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due ...
CVE-2026-92608HIGH7.5Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated messa...
CVE-2026-89426HIGH8.8The Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPress is vulnerable to Privilege Escalation...
CVE-2026-89406HIGH7.5The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of p...
CVE-2026-84280HIGH7.2The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Order 'elemen...
CVE-2026-19804HIGH8.8The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin...
CVE-2026-13456HIGH7.5The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnera...
CVE-2026-96039HIGH7.2The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via first_name Parameter in all...
CVE-2026-93303HIGH7.2The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored DOM-Based Cros...
CVE-2026-84281HIGH7.2The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'productTitle' in '_fpd...
CVE-2026-84279HIGH7.2The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'output_format' par...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now