2026 CVE Vulnerabilities

67,237 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-25265HIGH8.8Privilege escalation due to weak configuration while temporary file handling.
CVE-2026-25264HIGH8.8Privilege escalation due to weak configuration during package extraction process.
CVE-2026-25262MEDIUM6.9Memory corruption while processing a crafted ELF file in the Primary Bootloader.
CVE-2026-25255HIGH8.8Exposed dangerous function lead to privilege escalation via gRPC server.
CVE-2026-25254CRITICAL9.8Improper authorization leads to Remote Code Execution via SocketIO interface.
CVE-2026-9231HIGH7.5The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inc...
CVE-2026-95511——Rejected reason: Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in Sys...
CVE-2026-95508HIGH7.4A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured...
CVE-2026-93928HIGH7.3Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCo...
CVE-2026-93556CRITICAL9.3The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose passwor...
CVE-2026-89422CRITICAL9.3Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client c...
CVE-2026-68956HIGH7.1Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated remote atta...
CVE-2026-65634HIGH8.2Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated atta...
CVE-2026-15095MEDIUM4.9The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress is vu...
CVE-2026-9004MEDIUM4.3The WP-CRM System – Manage Clients and Projects plugin for WordPress is vulnerable to Sensitive Information Exposure in ...
CVE-2026-95503MEDIUM6.8A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution...
CVE-2026-93952CRITICAL10VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privile...
CVE-2026-93836HIGH7.2The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qty' ...
CVE-2026-93778HIGH7.2The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (import...
CVE-2026-92969HIGH8.1The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Local File Inclusion in a...
CVE-2026-92235HIGH8.1The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, an...
CVE-2026-91092MEDIUM4.3The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5....
CVE-2026-87082HIGH7.5Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in...
CVE-2026-87081HIGH7.5Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label...
CVE-2026-87080CRITICAL9.1Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now