2026 CVE Vulnerabilities

61,338 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-52751HIGH8.8Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code th...
CVE-2026-52750HIGH8.4Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metach...
CVE-2026-49498HIGH8.8Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabas...
CVE-2026-49497MEDIUM4.6Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames ...
CVE-2026-49496MEDIUM6.9Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator ...
CVE-2026-49495MEDIUM6.7Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.parseTrie() that lacks...
CVE-2026-49069HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio a...
CVE-2026-24067HIGH8.4Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.too...
CVE-2026-24066HIGH8.4Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.too...
CVE-2026-11859LOW2An HTML injection vulnerability in the "fetch links" email sent by Thinkst Applied Research Canarytokens, enabling Inter...
CVE-2026-3018HIGH7.5The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in ...
CVE-2026-11853MEDIUM6.5Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages...
CVE-2026-11852MEDIUM6.5Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debus...
CVE-2026-9019MEDIUM6.4The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderCol...
CVE-2026-8853MEDIUM4.4The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all version...
CVE-2026-8613MEDIUM6.4The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widge...
CVE-2026-10721HIGH8.4Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the  in Permission, Cache, and...
CVE-2026-9067CRITICAL9.1The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend ...
CVE-2026-9060LOW3.5The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and o...
CVE-2026-8071HIGH8.8The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a cus...
CVE-2026-3326HIGH8.6The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL state...
CVE-2026-29116HIGH8.7A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially...
CVE-2026-29115MEDIUM6.9A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially c...
CVE-2026-29114LOW2.3A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that ...
CVE-2026-11815MEDIUM5.3An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could pote...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now