2026 CVE Vulnerabilities

65,056 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6414MEDIUM5.9@fastify/static versions 8.0.0 through 9.1.0 decode percent-encoded path separators (%2F) before filesystem resolution, ...
CVE-2026-5968——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-31843CRITICAL10The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update e...
CVE-2026-3489HIGH7.5The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to SQL Injection vi...
CVE-2026-3369MEDIUM5.4The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2026-3155LOW3.1The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to authorization bypass in versions up to, and...
CVE-2026-23772HIGH7.3Dell Storage Manager - Replay Manager for Microsoft Servers, version(s) 8.0, contain(s) an Improper Privilege Management...
CVE-2026-0718MEDIUM5.3The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthor...
CVE-2026-41035HIGH7.8In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiv...
CVE-2026-41034MEDIUM5ONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.c...
CVE-2026-41030MEDIUM6.2In ONLYOFFICE DesktopEditors before 9.3.0, the update service allows attackers to perform actions on files with SYSTEM p...
CVE-2026-3995MEDIUM4.4The OPEN-BRAIN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'API Key' settings field in all...
CVE-2026-3876HIGH7.2The Prismatic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prismatic_encoded' pseudo-short...
CVE-2026-3875MEDIUM6.4The BetterDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'betterdocs_feedback_form' shor...
CVE-2026-3861HIGH7.1LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web ...
CVE-2026-3355MEDIUM6.1The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘crsea...
CVE-2026-1620HIGH8.8The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and ...
CVE-2026-1572MEDIUM6.4The Livemesh Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cro...
CVE-2026-5050HIGH7.5The Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to Improper Verification of Cryptog...
CVE-2026-3773MEDIUM6.5The Accessibility Suite by Ability, Inc plugin for WordPress is vulnerable to SQL Injection via the 'scan_id' parameter ...
CVE-2026-3614HIGH8.8The AcyMailing plugin for WordPress is vulnerable to privilege escalation in all versions From 9.11.0 up to, and includi...
CVE-2026-3599HIGH7.5The Riaxe Product Customizer plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter keys within...
CVE-2026-3596CRITICAL9.8The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu...
CVE-2026-3595MEDIUM5.3The Riaxe Product Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu...
CVE-2026-3581MEDIUM5.3The Basic Google Maps Placemarks plugin for WordPress is vulnerable to authorization bypass in versions up to, and inclu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now