2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-27851CRITICAL9.1When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted...
CVE-2026-4827HIGH8.7CWE‑331: Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the networ...
CVE-2026-45218HIGH7.7Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Trave...
CVE-2026-45215MEDIUM5.3Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Retrieve Emb...
CVE-2026-45214HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpro Xpro Elemento...
CVE-2026-45213HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 BEAR wo...
CVE-2026-45212MEDIUM5.3Missing Authorization vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster wp-asset-clean-up allows Exploiting ...
CVE-2026-45211HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExpe...
CVE-2026-45210MEDIUM5.4Missing Authorization vulnerability in Broadstreet Broadstreet Ads broadstreet allows Exploiting Incorrectly Configured ...
CVE-2026-42742HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Views for WPF...
CVE-2026-42741HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Ninja Forms V...
CVE-2026-41713HIGH8.2A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an uninte...
CVE-2026-41712HIGH7.5Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in ...
CVE-2026-32684LOW2.9The application does not impose strict enough restrictions on directory access permissions, posing a risk that other mal...
CVE-2026-2465HIGH8.8Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry an...
CVE-2026-8162HIGH7.5multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/f...
CVE-2026-8161HIGH7.5multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/f...
CVE-2026-8159HIGH7.5multiparty@4.2.3 and lower versions are vulnerable to denial of service via regular expression backtracking in the Conte...
CVE-2026-8072CRITICAL9.2Insecure generation of credentials in the local SAT (Technical Support) access functionality of the Ingecon Sun EMS Boar...
CVE-2026-7428CRITICAL9.2Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have cre...
CVE-2026-6813MEDIUM4.4The Continually plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ...
CVE-2026-6800MEDIUM4.4The FastBots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to,...
CVE-2026-6001HIGH8.8Authorization bypass through User-Controlled key vulnerability in ABIS Technology Ltd. Co. BAPSİS allows Exploitation of...
CVE-2026-5029HIGH8.7A remote code execution vulnerability exists in Code Runner MCP Server when run with the --transport http option, which ...
CVE-2026-44412HIGH7.8A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5). The affected applications con...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now