2026 CVE Vulnerabilities

64,659 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8679HIGH7.5The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including...
CVE-2026-8381MEDIUM5.4A broken access control vulnerability exists in the TeamViewer DEX Platform (On‑Premises) prior version 9.2. Certain bac...
CVE-2026-7798MEDIUM5.4The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin f...
CVE-2026-7636MEDIUM4.3The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is vulnerable to Sensitive Informat...
CVE-2026-7615MEDIUM4.3The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2026-5072MEDIUM6.5A bitwise shift vulnerability in Zephyr's PTP subsystem allows a remote attacker to cause undefined behavior and potenti...
CVE-2026-9104MEDIUM6.4The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Draft Post Title in all versions up...
CVE-2026-9018HIGH8.8The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation ...
CVE-2026-7509MEDIUM6.4The KIA Subtitle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `the-subtitle` short...
CVE-2026-7249MEDIUM4.3The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability c...
CVE-2026-6864MEDIUM6.1The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' param...
CVE-2026-4070MEDIUM4.3The Alfie – Feed Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2026-44409HIGH7.5There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control m...
CVE-2026-3481MEDIUM6.1The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode' parameter in al...
CVE-2026-2518MEDIUM4.3The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and activation due to missing ca...
CVE-2026-9054CRITICAL9.2An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size would trigger a kernel p...
CVE-2026-9053MEDIUM6.9Mothra would respect a default value given by a website for HTML file upload forms. An attacker could craft a website wi...
CVE-2026-4834HIGH7.5The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in all versions up to,...
CVE-2026-46598MEDIUM5.3For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when ...
CVE-2026-46597HIGH7.5An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafte...
CVE-2026-46595CRITICAL10Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of cal...
CVE-2026-42508CRITICAL9.1Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and...
CVE-2026-39835MEDIUM5.3SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be c...
CVE-2026-39834CRITICAL9.1When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload ...
CVE-2026-39833CRITICAL9.1The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enf...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now