2026 CVE Vulnerabilities

44,996 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-58078HIGH8.7Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extensio...
CVE-2026-15103HIGH8.8The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Pr...
CVE-2026-15008HIGH8.1The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnera...
CVE-2026-15005HIGH8.8The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2026-13741HIGH8.8The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all v...
CVE-2026-12978HIGH7.1The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the ...
CVE-2026-12585HIGH8.1The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recover...
CVE-2026-12525HIGH8.8The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving cus...
CVE-2026-53366HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on the paged allocation p...
CVE-2026-13042HIGH7.2The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions...
CVE-2026-21729HIGH7.5Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depe...
CVE-2026-12753HIGH7.5The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Inject...
CVE-2026-48863HIGH7.5A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to...
CVE-2026-3842HIGH7.8A flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine to write data beyond...
CVE-2026-23538HIGH7.5A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote attackers to establi...
CVE-2026-1609HIGH8.1A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user ac...
CVE-2026-15907HIGH7.3A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=...
CVE-2026-63175HIGH7.1PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level variables rather than in...
CVE-2026-55576HIGH8.8MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/r...
CVE-2026-55234HIGH8.5Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.j...
CVE-2026-53445HIGH7.1Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan copyBoard Meteor DDP method in server/publicatio...
CVE-2026-53444HIGH7.6Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan OIDC-related Meteor methods in packages/wekan-oidc/o...
CVE-2026-52890HIGH7.1Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachm...
CVE-2026-49279HIGH7.7WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the aut...
CVE-2026-48795HIGH8.6AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now