2026 CVE Vulnerabilities

61,215 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-39574CRITICAL9.3Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.
CVE-2026-39490HIGH7.5Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.
CVE-2026-39437HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 versions.
CVE-2026-2381MEDIUM6.5The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a ...
CVE-2026-10825HIGH7.1A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based ...
CVE-2026-8444HIGH8.8The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpf...
CVE-2026-46331HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page ca...
CVE-2026-10093MEDIUM6.4The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2026-9187MEDIUM5.3The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up t...
CVE-2026-8443HIGH8.8The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameter...
CVE-2026-6933HIGH8.8The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in version...
CVE-2026-5149MEDIUM6.5The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 Thi...
CVE-2026-50255MEDIUM6.7Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulne...
CVE-2026-10780MEDIUM4.3The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu...
CVE-2026-10635MEDIUM6.3On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core/ptables.c) maintain...
CVE-2026-6964MEDIUM5.3The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i...
CVE-2026-7273HIGH8.8A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABT...
CVE-2026-42014MEDIUM6.6A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can ...
CVE-2026-1767HIGH8.1A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` compo...
CVE-2026-1766MEDIUM6.1A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracke...
CVE-2026-1765MEDIUM5.6A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This ...
CVE-2026-1764MEDIUM5.6A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially craf...
CVE-2026-12162MEDIUM5.5Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an ...
CVE-2026-12161HIGH8.8Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or mo...
CVE-2026-9262HIGH7.5Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now