2026 CVE Vulnerabilities

60,364 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-10850MEDIUM5.4Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when cre...
CVE-2026-9591MEDIUM6.9Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthent...
CVE-2026-55738HIGH8.8A stack-based buffer overflow exists in the raw_to_header function in src/microtar.c in rxi microtar 0.1.0. The function...
CVE-2026-54819CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listd...
CVE-2026-54818HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimsta...
CVE-2026-54817MEDIUM6.5Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recover...
CVE-2026-54816HIGH7.5Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remote Code ...
CVE-2026-54815CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shi...
CVE-2026-54814HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-54813HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force S...
CVE-2026-54809CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme GIFT4U ...
CVE-2026-54808CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Trave...
CVE-2026-54417HIGH8.7An integer overflow in the mtar_next function in src/microtar.c in rxi microtar 0.1.0 allows a remote attacker to cause ...
CVE-2026-54193HIGH7.7Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.
CVE-2026-52716MEDIUM6.5Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.
CVE-2026-52707HIGH8.1Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.
CVE-2026-49268CRITICAL9.1A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm c...
CVE-2026-49108CRITICAL9.8Unauthenticated PHP Object Injection in Moderno < 1.43 versions.
CVE-2026-40757HIGH8.1Unauthenticated PHP Object Injection in Château <= 1.2.1 versions.
CVE-2026-40756HIGH8.1Unauthenticated PHP Object Injection in Zoya <= 1.4 versions.
CVE-2026-40752HIGH8.1Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.
CVE-2026-40738HIGH8.1Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.
CVE-2026-40733HIGH8.1Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.
CVE-2026-40720HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions.
CVE-2026-39590HIGH8.1Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now