2026 CVE Vulnerabilities

43,225 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-16250CRITICAL9.8The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an un...
CVE-2026-16060CRITICAL9.8The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the conten...
CVE-2026-15930CRITICAL9.4The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration bef...
CVE-2026-14557CRITICAL9.1The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token i...
CVE-2026-12965CRITICAL9.1The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action befo...
CVE-2026-12872CRITICAL9.8The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload ...
CVE-2026-58062CRITICAL9.3In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This i...
CVE-2026-8763CRITICAL9.3In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also a...
CVE-2026-59650CRITICAL9.3In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects...
CVE-2026-59638CRITICAL9.3In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. ...
CVE-2026-65321CRITICAL9.8PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrar...
CVE-2026-68582CRITICAL9.3Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-col...
CVE-2026-68579CRITICAL9.6FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_...
CVE-2026-16256CRITICAL9.8The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions av...
CVE-2026-8457CRITICAL9.8The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and inc...
CVE-2026-67342CRITICAL9.8ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, P...
CVE-2026-67341CRITICAL9.8ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with...
CVE-2026-67340CRITICAL9.8ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) b...
CVE-2026-67336CRITICAL9.4better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that adve...
CVE-2026-67330CRITICAL9.9@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7....
CVE-2026-67324CRITICAL9.8GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>...
CVE-2026-67308CRITICAL9.3Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execut...
CVE-2026-67305CRITICAL9.4FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when...
CVE-2026-67294CRITICAL9.3FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-si...
CVE-2026-67293CRITICAL9.3FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now