2026 CVE Vulnerabilities

44,810 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-14293HIGH8.8The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option ...
CVE-2026-14238MEDIUM4.1The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body...
CVE-2026-14237HIGH7.2The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorizat...
CVE-2026-14211LOW3.8The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated empl...
CVE-2026-14206HIGH7.5The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns...
CVE-2026-13701MEDIUM4.8The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outputting it o...
CVE-2026-13600HIGH8.1The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before settin...
CVE-2026-13170HIGH7.2The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to includ...
CVE-2026-13133HIGH8.4A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is lo...
CVE-2026-12971LOW2.2The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowi...
CVE-2026-12570MEDIUM5.5A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading maliciou...
CVE-2026-17519Rejected reason: This is rejected.
CVE-2026-72522MEDIUM6.2libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same ...
CVE-2026-19389HIGH7.1Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdem...
CVE-2026-19387HIGH7.6A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/D...
CVE-2026-19384HIGH7.3A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unkno...
CVE-2026-19383MEDIUM4.7A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shell_ex...
CVE-2026-19382LOW2.3A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan...
CVE-2026-19381HIGH7.8A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unkn...
CVE-2026-19380LOW2.3A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the...
CVE-2026-19379HIGH7.3A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of t...
CVE-2026-19378MEDIUM4.3A vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the...
CVE-2026-19376HIGH7.3A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class o...
CVE-2026-19375MEDIUM6.3A vulnerability was detected in dmitriiweb article-scraper-mcp 1.0.0. This vulnerability affects the function fetch_arti...
CVE-2026-19374HIGH7.3A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affect...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now