2026 CVE Vulnerabilities

61,161 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-49072MEDIUM6.5Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions.
CVE-2026-49071MEDIUM6.5Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions.
CVE-2026-49058CRITICAL9.8Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions.
CVE-2026-49057HIGH7.5Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions.
CVE-2026-48967HIGH8.5Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions.
CVE-2026-48929HIGH7.5Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthent...
CVE-2026-48875CRITICAL9.3Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions.
CVE-2026-48869HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions.
CVE-2026-48797CRITICAL9.3Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, th...
CVE-2026-48788HIGH8.2Remark42 is a self-hosted comment engine for blogs, articles, or any other place where readers can add comments. Version...
CVE-2026-48783MEDIUM4.8Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accept...
CVE-2026-48782MEDIUM6.8Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 t...
CVE-2026-48781CRITICAL9.9Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an atta...
CVE-2026-48779HIGH7.5ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, f...
CVE-2026-48745CRITICAL9.3Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Tracca...
CVE-2026-48616CRITICAL9.3Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in L...
CVE-2026-48055CRITICAL10Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior,...
CVE-2026-47340MEDIUM6.5Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. ...
CVE-2026-47277MEDIUM6.5Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos fro...
CVE-2026-45436MEDIUM6.5Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions.
CVE-2026-44587MEDIUM6.1CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_typ...
CVE-2026-42629HIGH8.8Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions.
CVE-2026-42385HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions.
CVE-2026-42380CRITICAL9.8Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions.
CVE-2026-42357MEDIUM6.5Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now