2026 CVE Vulnerabilities

60,251 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40457LOW2.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in LMS (LAN Management System) before commit 9c5651b in the ...
CVE-2026-40456HIGH8.6An OS Command Injection vulnerability exists in LMS (LAN Management System) before commit 9fcb4de due to an IP address p...
CVE-2026-40455HIGH8.6An SQL Injection vulnerability exists in LMS (LAN Management System) before commit 4cb30a7 within the "tarifflist.php" m...
CVE-2026-12539MEDIUM5.7Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-appl...
CVE-2026-12527MEDIUM6A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V3...
CVE-2026-12039MEDIUM5.7Docker Sandboxes (sbx) enforces an HTTP/S-only egress allowlist but does not apply it to DNS resolution: the per-network...
CVE-2026-11958HIGH7.3Local privilege escalation by loading DLLs from a shared temporary directory in ANSSI’s DFIR-ORC, versions 10.2.7 and pr...
CVE-2026-11719HIGH8.1An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement...
CVE-2026-11718CRITICAL9.1An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googl...
CVE-2026-11717CRITICAL9.1An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googl...
CVE-2026-8811HIGH7.1SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An atta...
CVE-2026-8039MEDIUM6.4The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' shortcode attr...
CVE-2026-50643MEDIUM5.18cc is vulnerable to an Out‑of‑Bounds Read due to improper handling of #line directives and GNU linemarkers. The compile...
CVE-2026-2021MEDIUM6.4The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alwaysauto' shortc...
CVE-2026-9815MEDIUM6.5The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenti...
CVE-2026-55746HIGH7.6Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in the Personal File Storage...
CVE-2026-55745MEDIUM5.4Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage ...
CVE-2026-55744HIGH8.6Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage ...
CVE-2026-55742CRITICAL9.6Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights ...
CVE-2026-55741HIGH8.8Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configu...
CVE-2026-28573MEDIUM5.5In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could l...
CVE-2026-12137MEDIUM6.1The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is...
CVE-2026-12136MEDIUM6.4The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysb...
CVE-2026-12111MEDIUM4.3The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to,...
CVE-2026-12102LOW2.7The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now