2026 CVE Vulnerabilities

65,056 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-3551MEDIUM4.4The Custom New User Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's admi...
CVE-2026-22619CRITICAL9.9Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to a...
CVE-2026-22618HIGH7.1A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was...
CVE-2026-22617HIGH7.4Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacke...
CVE-2026-40118MEDIUM6.3UDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability....
CVE-2026-22616HIGH7.5Eaton Intelligent Power Protector (IPP) software allows repeated authentication attempts against the web interface login...
CVE-2026-22615HIGH7.2Due to improper input validation in one of the Eaton Intelligent Power Protector (IPP) XML, it is possible for an attack...
CVE-2026-5070MEDIUM6.4The Vantage theme for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery block text content in versions ...
CVE-2026-4032MEDIUM6.1The CodeColorer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in 'cc' comm...
CVE-2026-3878MEDIUM6.4The WP Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdocs_options[icon_size]' parame...
CVE-2026-6351HIGH8.7MailGates/MailAudit developed by Openfind has a CRLF Injection vulnerability, allowing unauthenticated remote attackers ...
CVE-2026-6350CRITICAL9.8MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remo...
CVE-2026-6349CRITICAL9.8The  iSherlock developed by HGiga  has an OS Command Injection vulnerability, allowing unauthenticated local attackers t...
CVE-2026-6348CRITICAL9.3WinMatrix agent developed by Simopro Technology has a Missing Authentication vulnerability, allowing authenticated local...
CVE-2026-41015HIGH7.4radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE...
CVE-2026-3885MEDIUM6.4The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2026-3428MEDIUM5.4A Download of Code Without Integrity Check vulnerability in the update modules in ASUS Member Center(华硕大厅) allows a loca...
CVE-2026-1880MEDIUM5.4An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privi...
CVE-2026-40962CRITICAL9.8FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data ...
CVE-2026-40505MEDIUM4.8MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI esca...
CVE-2026-40504CRITICAL9.8Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows ...
CVE-2026-3299MEDIUM6.4The WP YouTube Lyte plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lyte' shortcode ...
CVE-2026-40960HIGH8.1Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as s...
CVE-2026-40959CRITICAL9.3Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod.
CVE-2026-40503HIGH7.1OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now