2026 CVE Vulnerabilities

61,264 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-1291MEDIUM4.3The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che...
CVE-2026-11624CRITICAL9.4The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming conne...
CVE-2026-9629MEDIUM6.4The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up ...
CVE-2026-3297MEDIUM6.4The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2026-2470MEDIUM4.3The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Incorrect Authorizatio...
CVE-2026-9134MEDIUM6.4The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcod...
CVE-2026-9109HIGH7.2The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is vu...
CVE-2026-9062LOW3.4The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing h...
CVE-2026-9061LOW3.5The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and o...
CVE-2026-11769HIGH8.8We have released version 5.24.0 of the Grafana Operator. This patch includes a MEDIUM severity security fix for a path t...
CVE-2026-9848HIGH7.5The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in vers...
CVE-2026-54231MEDIUM5.5A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script...
CVE-2026-54230HIGH7.8A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts wr...
CVE-2026-54229HIGH7A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump direc...
CVE-2026-54228HIGH7.8A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Betwee...
CVE-2026-12089MEDIUM4.9The LWS Optimize – All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbitrary File Read in v...
CVE-2026-11443MEDIUM4.6Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote at...
CVE-2026-11442MEDIUM6.5Allegra exportReport Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attacker...
CVE-2026-6676HIGH7.8Heap buffer out-of-bounds write vulnerability in Avira Antivirus engine when scanning a malformed POSIX tar archive may ...
CVE-2026-12068HIGH7.4Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may allow a remote attacke...
CVE-2026-54398MEDIUM5.3An authorization flaw in MISP’s object add/edit handling allowed an authenticated user with object editing permissions t...
CVE-2026-54095Rejected reason: CVE ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-53826. Reason: This candidate i...
CVE-2026-53868HIGH8.7Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary...
CVE-2026-53867MEDIUM5.3Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remo...
CVE-2026-53839MEDIUM6.5OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching host...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now