2026 CVE Vulnerabilities

64,848 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-43870HIGH7.3Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutra...
CVE-2026-43868MEDIUM5.3Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0....
CVE-2026-3601MEDIUM4.3The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a miss...
CVE-2026-3359HIGH7.5The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Inj...
CVE-2026-43869HIGH7.3Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift:...
CVE-2026-7824MEDIUM5.9An issue was discovered in the PaperCut Hive Ricoh embedded application. When the "Deep Logging" (diagnostic) mode is en...
CVE-2026-6418MEDIUM4.9An issue was discovered in the Shared Account Synchronization component of PaperCut MF (version 25.0.4). The application...
CVE-2026-6180HIGH8.1A race condition exists in PaperCut MF when processing badge-swipe data from certain HP multifunction devices. Under spe...
CVE-2026-5192HIGH7.5The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Path Trave...
CVE-2026-40797CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder LLC We...
CVE-2026-3454MEDIUM6.5The GenerateBlocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inc...
CVE-2026-2729MEDIUM5.3The Forminator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.52.0. ...
CVE-2026-7823CRITICAL9.8A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg of...
CVE-2026-7822MEDIUM6.3A vulnerability was identified in itsourcecode Courier Management System 1.0. This impacts an unknown function of the fi...
CVE-2026-7812HIGH7.3A vulnerability was found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8. The impacted element is the...
CVE-2026-7811HIGH7.3A vulnerability has been found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8. The affected element i...
CVE-2026-4362MEDIUM6.5The ElementsKit Elementor Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missin...
CVE-2026-7810HIGH7.3A flaw has been found in UsamaK98 python-notebook-mcp up to a05a232815809a7e425b5fa7be26e0d4369894c2. Impacted is the fu...
CVE-2026-5957MEDIUM6.5The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to and including 1.6.5. This i...
CVE-2026-5294CRITICAL9.8The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. This ...
CVE-2026-5159MEDIUM6.4The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed ...
CVE-2026-4803HIGH7.2The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter ...
CVE-2026-4665MEDIUM6.4The WP Carousel Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted fancybox `data-captio...
CVE-2026-3456HIGH7.5The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to SQL...
CVE-2026-35228HIGH8.7Vulnerability in the Oracle MCP Server Helper Tool product of Oracle Open Source Projects (component: helper tool). The ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now