2026 CVE Vulnerabilities

63,662 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-49198MEDIUM4.9Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorize...
CVE-2026-49197CRITICAL9.8Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requ...
CVE-2026-49196HIGH7.2The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitrary she...
CVE-2026-49195HIGH8.8Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any...
CVE-2026-10058MEDIUM4.8ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privi...
CVE-2026-10057MEDIUM4.8ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privi...
CVE-2026-10056HIGH7.5CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default ...
CVE-2026-10052MEDIUM4.1A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can...
CVE-2026-10039MEDIUM4.9The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter i...
CVE-2026-9243MEDIUM6.4The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direct...
CVE-2026-4776HIGH7.1An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitiz...
CVE-2026-49322MEDIUM4.3Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year al...
CVE-2026-3655CRITICAL9.8The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in version...
CVE-2026-9714MEDIUM6.4The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of th...
CVE-2026-9493HIGH7.1Service Center developed by BankPro E-Service Technology has an Insecure Direct Object Reference vulnerability, allowing...
CVE-2026-8732CRITICAL9.8The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all ver...
CVE-2026-6324MEDIUM4.8A flaw was found in libsoup. A remote attacker could exploit an unsigned to signed conversion error in the `soup_body_in...
CVE-2026-6275MEDIUM6.4The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in vers...
CVE-2026-2128MEDIUM5.3The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versi...
CVE-2026-8995MEDIUM4.3The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Sensitive Information ...
CVE-2026-7430MEDIUM4.4The Post Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including...
CVE-2026-8070HIGH7.3Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the driver’s vali...
CVE-2026-7480HIGH7.3An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local u...
CVE-2026-6892MEDIUM5.1Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with...
CVE-2026-6891MEDIUM5.1Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a l...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now