2026 CVE Vulnerabilities

44,976 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-14526CRITICAL9.8The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and...
CVE-2026-18988MEDIUM6.4The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block a...
CVE-2026-13505HIGH8.7In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X ser...
CVE-2026-8798HIGH8.7In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried ...
CVE-2026-52880HIGH7.5Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable...
CVE-2026-52879HIGH7.5Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-mess...
CVE-2026-52878HIGH7.5Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a...
CVE-2026-49343MEDIUM5.9Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie...
CVE-2026-48122MEDIUM5.4Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP...
CVE-2026-48120HIGH8.6Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be ...
CVE-2026-48047MEDIUM5.9XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to ...
CVE-2026-48026HIGH8.7lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of th...
CVE-2026-47249HIGH7.5Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling...
CVE-2026-47127MEDIUM6.5Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-UR...
CVE-2026-46409CRITICAL9.6OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to v...
CVE-2026-64676MEDIUM5.7Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In ...
CVE-2026-58262HIGH7.1Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification cou...
CVE-2026-48170CRITICAL9.1`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM ...
CVE-2026-48169HIGH8.8PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization fa...
CVE-2026-47243CRITICAL9.2Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th...
CVE-2026-46405MEDIUM5.3OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth m...
CVE-2026-45808HIGH7.1OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide...
CVE-2026-11743MEDIUM6.6The SF32LB MPI QSPI NOR flash driver (drivers/flash/flash_sf32lb_mpi_qspi_nor.c) validated the flash offset and length o...
CVE-2026-11742LOW3.6The kernel queue helper z_queue_node_peek() in kernel/queue.c dereferences a node taken from a queue's data_q list, read...
CVE-2026-9031MEDIUM6.8An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied da...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now