2026 CVE Vulnerabilities

60,195 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-12094MEDIUM5.3The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a mi...
CVE-2026-11997MEDIUM4.3The Bulk SEO Image plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1....
CVE-2026-11370MEDIUM6.4The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ...
CVE-2026-10753LOW2.7The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administ...
CVE-2026-10749HIGH7.2The Post Duplicator WordPress plugin before 3.0.15 does not safely handle custom meta-data during post duplication, stor...
CVE-2026-10735HIGH7.5Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, P...
CVE-2026-10552MEDIUM4.3The Blue Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 2.0.1....
CVE-2026-10531MEDIUM5.4The AI Share & Summarize WordPress plugin before 2.0.4 does not sanitise and escape some of its shortcode attributes bef...
CVE-2026-10092HIGH7.2The Cincopa video and media plug-in plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cincopa Shortc...
CVE-2026-10091HIGH7.2The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' sh...
CVE-2026-9539MEDIUM6.5An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp...
CVE-2026-12851CRITICAL9.1Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09...
CVE-2026-12850CRITICAL9.1Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09...
CVE-2026-12849CRITICAL9.1Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09...
CVE-2026-12848CRITICAL10GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48...
CVE-2026-12847CRITICAL10GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48...
CVE-2026-12846CRITICAL10GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48...
CVE-2026-12488MEDIUM6.2A memory corruption vulnerability exists in the GV-Cloud functionality of GeoVision GV-VMS V20 20.0.2.  A specially cr...
CVE-2026-12486CRITICAL9.1Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09...
CVE-2026-12485CRITICAL10GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48...
CVE-2026-3652HIGH7.2The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf_save...
CVE-2026-11614MEDIUM6.4The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '...
CVE-2026-12681HIGH8.9Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation. parseEfiSig...
CVE-2026-54639HIGH8.8Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulnerability starting in...
CVE-2026-7574HIGH8.7Anthropic Claude Desktop Cowork VM image handling (confirmed across v1.1348.0 through v1.2278.0, including v1.1348.0, v1...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now