2026 CVE Vulnerabilities

61,069 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-11719HIGH8.1An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement...
CVE-2026-11718CRITICAL9.1An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googl...
CVE-2026-11717CRITICAL9.1An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googl...
CVE-2026-8811HIGH7.1SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An atta...
CVE-2026-8039MEDIUM6.4The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' shortcode attr...
CVE-2026-50643MEDIUM5.18cc is vulnerable to an Out‑of‑Bounds Read due to improper handling of #line directives and GNU linemarkers. The compile...
CVE-2026-2021MEDIUM6.4The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alwaysauto' shortc...
CVE-2026-9815MEDIUM6.5The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenti...
CVE-2026-55746HIGH7.6Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in the Personal File Storage...
CVE-2026-55745MEDIUM5.4Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage ...
CVE-2026-55744HIGH8.6Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage ...
CVE-2026-55742CRITICAL9.6Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights ...
CVE-2026-55741HIGH8.8Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configu...
CVE-2026-28573MEDIUM5.5In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could l...
CVE-2026-12137MEDIUM6.1The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is...
CVE-2026-12136MEDIUM6.4The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysb...
CVE-2026-12111MEDIUM4.3The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to,...
CVE-2026-12102LOW2.7The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre...
CVE-2026-12098MEDIUM6.4The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed...
CVE-2026-11395HIGH7.2The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin...
CVE-2026-9860HIGH8.8The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all ver...
CVE-2026-9199MEDIUM4.3The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerabl...
CVE-2026-55740CRITICAL9.8Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthe...
CVE-2026-12120MEDIUM5.3The FireBox Popups – Increase Sales and Grow Your Email List plugin for WordPress is vulnerable to Sensitive Information...
CVE-2026-12093MEDIUM5.3The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now