2026 CVE Vulnerabilities

64,952 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4106MEDIUM5.3The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some P...
CVE-2026-41040HIGH8.7GROWI provided by GROWI, Inc. is vulnerable to a regular expression denial of service (ReDoS) via a crafted input string...
CVE-2026-34488HIGH7.3IP Setting Software contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Librar...
CVE-2026-41990MEDIUM4Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attack...
CVE-2026-41989MEDIUM6.7Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext ...
CVE-2026-41988LOW2.5uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6....
CVE-2026-41233MEDIUM5.4Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` paramet...
CVE-2026-41232MEDIUM5Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain owner...
CVE-2026-40529MEDIUM5.1CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in the database may be ...
CVE-2026-41231HIGH7.5Froxlor is open source server administration software. Prior to version 2.3.6, `DataDump.add()` constructs the export de...
CVE-2026-41230HIGH8.5Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DN...
CVE-2026-41229CRITICAL9.1Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes ...
CVE-2026-41228CRITICAL9.9Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.updat...
CVE-2026-3361MEDIUM6.4The WP Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpsl_address' post meta ...
CVE-2026-3007MEDIUM5.4Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitr...
CVE-2026-3844CRITICAL9.8The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the...
CVE-2026-2951MEDIUM5.4The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2026-41679CRITICAL10Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 202...
CVE-2026-41243MEDIUM5.4OpenLearn is open-source educational forum software. Prior to commit 844b2a40a69d0c4911580fe501923f0b391313ab, when `saf...
CVE-2026-41211CRITICAL10Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` ac...
CVE-2026-41208HIGH8.8Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @papercl...
CVE-2026-41206HIGH7.8PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. The...
CVE-2026-41200HIGH8.5STIG Manager is an API and web client for managing Security Technical Implementation Guides (STIG) assessments of Infor...
CVE-2026-41197CRITICAL9.3Noir is a Domain Specific Language for SNARK proving systems that is designed to use any ACIR compatible proving system,...
CVE-2026-41196CRITICAL10Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to versio...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now