2026 CVE Vulnerabilities

67,214 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-91799HIGH7.8A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of JavaScript array objects. A specially cra...
CVE-2026-91798HIGH8.8A local privilege escalation vulnerability exists in the update daemon of Foxit PDF Editor/Reader due to an insecure per...
CVE-2026-91797HIGH7.8Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malici...
CVE-2026-91796MEDIUM6.1The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows special...
CVE-2026-91795HIGH7.8Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted P...
CVE-2026-91794HIGH7.8An out-of-bounds write vulnerability exists in the PDF rendering process of Foxit PDF Editor/Reader due to insufficient ...
CVE-2026-91793HIGH7.8When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotation rich-text attribut...
CVE-2026-91792HIGH7.8When processing a specially crafted PDF, Foxit PDF Editor/Reader may perform reentrant zoom and layout operations throug...
CVE-2026-91791HIGH7.8When processing a specially crafted PDF file, Foxit PDF Editor/Reader may encounter a reentrant execution condition invo...
CVE-2026-91790HIGH7.8When rendering the page image, Foxit PDF Editor/Reader fails to perform validation on image objects whose optional conte...
CVE-2026-91789HIGH7.8Foxit PDF Editor/Reader’s U3D/GIF texture decoding path contained insufficient validation of image dimensions and relate...
CVE-2026-91788MEDIUM4.7When implementing the JavaScript interface, Foxit PDF Editor/Reader did not perform the attribute authorization checks r...
CVE-2026-50228MEDIUM6.1An unauthenticated local attacker can connect to the Electron DevTools endpoint exposed by Acer NitroSense software (ver...
CVE-2026-50227MEDIUM6.1An unauthenticated local attacker can connect to the MQTT broker over its localhost WebSocket endpoint in Acer NitroSens...
CVE-2026-82331CRITICAL9.8Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildS...
CVE-2026-6831MEDIUM6.5The Advanced Contact form 7 DB plugin for WordPress is vulnerable to missing authorization in all versions up to, and in...
CVE-2026-5924MEDIUM6.4The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps bloc...
CVE-2026-93528LOW3.7The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an ...
CVE-2026-93511MEDIUM5.3The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature before processing payment...
CVE-2026-93510MEDIUM4.3The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not validate the claimed reward amount or res...
CVE-2026-93508HIGH8.1The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX acti...
CVE-2026-93507LOW3.3The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post...
CVE-2026-91077LOW2.7The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to ev...
CVE-2026-91073MEDIUM6.8The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputti...
CVE-2026-91025MEDIUM4.3The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager W...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now