2026 CVE Vulnerabilities

67,200 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-93529MEDIUM6.5Contributor Broken Access Control in WSP MCP &#8211; AI Agents Connector <= 2.7.0 versions.
CVE-2026-93527HIGH8.5Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions.
CVE-2026-93526HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions.
CVE-2026-93513MEDIUM4.3Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions.
CVE-2026-93421MEDIUM5.3Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /_...
CVE-2026-92730HIGH7.4LimeSurvey Community Edition 7.0.14 contains a reflected cross-site scripting vulnerability on the administrative survey...
CVE-2026-92700MEDIUM6.3Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/fil...
CVE-2026-92692MEDIUM6.9Sulu is an open-source PHP content management system based on the Symfony framework. Prior to 2.6.25 and 3.0.8, the affe...
CVE-2026-92284MEDIUM6.9Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/rep...
CVE-2026-90905HIGH7.2Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension...
CVE-2026-90904HIGH8.6Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store ext...
CVE-2026-90903HIGH7.2Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Stor...
CVE-2026-90902HIGH8.6Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extensio...
CVE-2026-90901HIGH8.6Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extens...
CVE-2026-90900MEDIUM5.3Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Stor...
CVE-2026-90899HIGH8.2Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0....
CVE-2026-84502CRITICAL9.9A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not valid...
CVE-2026-84499HIGH7.7A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are ...
CVE-2026-84486HIGH8.2A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views that trigger the inte...
CVE-2026-84474CRITICAL9.9A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host...
CVE-2026-82368HIGH8.7Insecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow local, non-administrat...
CVE-2026-82356HIGH7.5Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key pair after deployment when generating an X.509 certificat...
CVE-2026-77602CRITICAL9.9OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2026-77601HIGH8.8OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2026-77423HIGH7.5JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in less viewer p...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now