2026 CVE Vulnerabilities

61,018 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56235MEDIUM6.9Cap-go capgo before 12.128.2 contains an authorization bypass in several Supabase PostgREST RPC functions (get_app_metri...
CVE-2026-56228MEDIUM6.9Capgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password policy confi...
CVE-2026-56227MEDIUM5.4Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows loopbac...
CVE-2026-56218MEDIUM6.9Capgo before 12.128.2 fails to strip EXIF metadata including GPS geolocation data from uploaded images, allowing informa...
CVE-2026-12673MEDIUM5.9Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalati...
CVE-2026-48939CRITICAL9.8A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature...
CVE-2026-48909CRITICAL9.5SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauth...
CVE-2026-48908CRITICAL9.8A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulti...
CVE-2026-12119MEDIUM6.5The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization c...
CVE-2026-11912HIGH7.5The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization...
CVE-2026-11911HIGH7.5The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat...
CVE-2026-9843HIGH8.1The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion ...
CVE-2026-9265CRITICAL9.1Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path. print_...
CVE-2026-56216HIGH8.8Capgo before 12.128.2 contains a scope escalation vulnerability in the POST /functions/v1/apikey endpoint that allows ap...
CVE-2026-56215HIGH8.7Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbitrary addresses, whi...
CVE-2026-56214HIGH8.7Capgo before 12.128.2 contains an information disclosure vulnerability in Supabase PostgREST RPC endpoints is_trial_org ...
CVE-2026-56213MEDIUM6.9Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.upsert_version_meta SECURITY DEFINER ...
CVE-2026-56212MEDIUM5.1Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization secur...
CVE-2026-11551CRITICAL9.8The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and in...
CVE-2026-56082HIGH8.7Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST...
CVE-2026-56081CRITICAL9.3Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound...
CVE-2026-56080MEDIUM6.9Capgo before 12.128.2 contains a flaw in the Enforce Password Policy feature: after a Super Admin enables the policy and...
CVE-2026-56079HIGH7.1Capgo before 12.128.2 contains a cross-tenant authorization bypass vulnerability in PostgREST endpoints that allows org-...
CVE-2026-56073CRITICAL9.4Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypa...
CVE-2026-50559HIGH7.5Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now