2026 CVE Vulnerabilities

61,215 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-12293CRITICAL9.8Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
CVE-2026-12292HIGH8.1Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.1...
CVE-2026-12291HIGH8.8Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firef...
CVE-2026-12290HIGH8.1Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115...
CVE-2026-12289HIGH8.8Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140....
CVE-2026-8484MEDIUM4.8A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper due to a lack of size verification for th...
CVE-2026-40750CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Sh...
CVE-2026-12225HIGH8.7syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vu...
CVE-2026-10829HIGH8.6A stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and earli...
CVE-2026-10828MEDIUM6.9A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPor...
CVE-2026-8442HIGH8.1The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 1...
CVE-2026-8176HIGH7.5The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Esca...
CVE-2026-5416HIGH8.8Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exp...
CVE-2026-54198HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions.
CVE-2026-54197MEDIUM6.5Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions.
CVE-2026-54191HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions.
CVE-2026-54190MEDIUM6.5Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.
CVE-2026-52715CRITICAL9.3Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions.
CVE-2026-52714MEDIUM5.9Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= 12.4.16 versions.
CVE-2026-52712HIGH7.6Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions.
CVE-2026-52711HIGH7.5Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.
CVE-2026-49774CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inc...
CVE-2026-49772CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / Stell...
CVE-2026-40809MEDIUM6.5Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Contro...
CVE-2026-39581HIGH8.5Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now