2026 CVE Vulnerabilities

64,602 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-49053MEDIUM5.3Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured ...
CVE-2026-49052MEDIUM4.3Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured ...
CVE-2026-49051MEDIUM4.3Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured...
CVE-2026-49047MEDIUM4.3Missing Authorization vulnerability in DearHive DearFlip allows Exploiting Incorrectly Configured Access Control Securit...
CVE-2026-49046HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arjun Thakur Dupli...
CVE-2026-49045MEDIUM4.3Missing Authorization vulnerability in WP Media Adminimize allows Exploiting Incorrectly Configured Access Control Secur...
CVE-2026-49044MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Kruit Advan...
CVE-2026-48973MEDIUM4.3Missing Authorization vulnerability in Benbodhi SVG Support allows Exploiting Incorrectly Configured Access Control Secu...
CVE-2026-48927MEDIUM5.5Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting...
CVE-2026-48926MEDIUM4.3Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allow...
CVE-2026-48925MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration Plugin 0.7.3 and earlier allows attacker...
CVE-2026-48924MEDIUM4.3Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to pe...
CVE-2026-48923MEDIUM4.3Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation...
CVE-2026-48922HIGH7.5Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip...
CVE-2026-48921HIGH7.5Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared l...
CVE-2026-48920HIGH8.8Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by set...
CVE-2026-48919MEDIUM6.6Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.
CVE-2026-48918MEDIUM6.6Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.
CVE-2026-48917MEDIUM6.6Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation.
CVE-2026-48916MEDIUM6.6Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals.
CVE-2026-48545MEDIUM6.8Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Spa...
CVE-2026-48544HIGH8.7Taipy 4.1.1, fixed in commit 129fd40, contains a path traversal vulnerability in the ElementLibrary.get_resource() metho...
CVE-2026-47119MEDIUM6.1Agent Zero before version 1.15 contains a stored cross-site scripting vulnerability that allows attackers to execute arb...
CVE-2026-47118HIGH7.1Agent Zero before version 1.15 contains a path traversal vulnerability that allows unauthenticated attackers to read arb...
CVE-2026-45571MEDIUM5.4go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now