2026 CVE Vulnerabilities

64,760 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6415MEDIUM6.4The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u...
CVE-2026-6403HIGH7.5The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is...
CVE-2026-6228HIGH8.8The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and includ...
CVE-2026-5229CRITICAL9.8The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This...
CVE-2026-4683MEDIUM6.5The Smartcat Translator for WPML plugin for WordPress is vulnerable to unauthorized modification of data due to a missin...
CVE-2026-44088HIGH8.6SzafirHost verifies the signature of the downloaded JAR file using class JarInputStream (reading from the beginning of t...
CVE-2026-8654HIGH8.7Improper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operat...
CVE-2026-6646MEDIUM6.4The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dt_default_button' shortcode in all v...
CVE-2026-4094HIGH8.1The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss du...
CVE-2026-41702HIGH7VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a...
CVE-2026-43490HIGH8.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate inherited ACE SID length smb_inher...
CVE-2026-28761HIGH8.5Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 a...
CVE-2026-24662MEDIUM5.4Cross-site scripting vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and ear...
CVE-2026-0481CRITICAL9.2Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to per...
CVE-2026-7373HIGH8.5Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level contr...
CVE-2026-2652HIGH8.6A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when...
CVE-2026-0428LOW1.8Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_...
CVE-2026-0427MEDIUM4.6Improper cleanup of shared register resources in GPU firmware could allow an admin-privileged attacker from a Guest Virt...
CVE-2026-8612MEDIUM5.3WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cac...
CVE-2026-0438MEDIUM5.4A System Management Mode (SMM) handler could perform a callout to code located in non-SMM/untrusted memory. A highly pri...
CVE-2026-0432HIGH8.5Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achiev...
CVE-2026-6811HIGH7.5Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSO...
CVE-2026-45248MEDIUM6.9Hedera Guardian through 3.5.1 contains an authentication bypass vulnerability in the GET /api/v1/demo/registered-users e...
CVE-2026-44671HIGH7.5ZITADEL is an open source identity management platform. From 2.71.11 to before 3.4.10 and 4.15.0, a vulnerability was di...
CVE-2026-44428MEDIUM4.7The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.6, the...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now