2026 CVE Vulnerabilities

44,976 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-19279MEDIUM5.3A vulnerability was identified in MIMICLab mcp-pdf-vision 1.1.0. The impacted element is the function load_pdf of the fi...
CVE-2026-68082CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: libceph: fix two unsafe bare decodes in decode_lock...
CVE-2026-68081In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Put vmcs12 pages if nested VM-Enter fail...
CVE-2026-19270MEDIUM5.3A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0. Affected is the function get_journey/delete_jo...
CVE-2026-19268MEDIUM6.3A vulnerability was identified in abdullah1854 MCPGateway up to 549f494a9e363f40530149de324b8097de424230. This impacts t...
CVE-2026-19266MEDIUM5.5A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the f...
CVE-2026-19263HIGH7.3A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114. The impacted elem...
CVE-2026-19259MEDIUM5.3A vulnerability has been found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function MmsMapping...
CVE-2026-16955MEDIUM5The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwardi...
CVE-2026-16953MEDIUM4.8The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deleti...
CVE-2026-16948HIGH8.1The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exp...
CVE-2026-16608MEDIUM5.3The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging ...
CVE-2026-16595MEDIUM6.5The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti...
CVE-2026-16594HIGH7.5The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti...
CVE-2026-16590MEDIUM6.5The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti...
CVE-2026-16589HIGH7.7The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL sta...
CVE-2026-16578HIGH7.5The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does n...
CVE-2026-16574MEDIUM5.4The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that ...
CVE-2026-16562MEDIUM6.5The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics ...
CVE-2026-16559MEDIUM6.8The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload featur...
CVE-2026-16558MEDIUM5.4The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it...
CVE-2026-16535MEDIUM6.1The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a r...
CVE-2026-16282MEDIUM5.3The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against t...
CVE-2026-16269MEDIUM4.8The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthentica...
CVE-2026-16267HIGH8.1The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now