2026 CVE Vulnerabilities

65,063 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4667HIGH7.3HP System Optimizer might potentially be vulnerable to escalation of privilege. HP is releasing an update to mitigate th...
CVE-2026-30364HIGH7.5CentSDR commit e40795 was discovered to contain a stack overflow in the "Thread1" function.
CVE-2026-4145HIGH7.8During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow...
CVE-2026-4135MEDIUM6.6During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during ins...
CVE-2026-4134HIGH7.3During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during ins...
CVE-2026-25219MEDIUM6.5The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. Thi...
CVE-2026-1636MEDIUM6.7A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allo...
CVE-2026-0827HIGH7.1During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareS...
CVE-2026-3590MEDIUM6.5Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic sin...
CVE-2026-1852MEDIUM6.1The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u...
CVE-2026-40786MEDIUM4.3Missing Authorization vulnerability in Long Watch Studio MyRewards woorewards allows Exploiting Incorrectly Configured A...
CVE-2026-40784HIGH8.1Authorization Bypass Through User-Controlled Key vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows ...
CVE-2026-40778MEDIUM5.3Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly ...
CVE-2026-40764HIGH8.1Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Cross Site Re...
CVE-2026-40763MEDIUM5.3Missing Authorization vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrec...
CVE-2026-40745HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bdthemes Element P...
CVE-2026-40744HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beaver Builder Bea...
CVE-2026-40742MEDIUM5.3Missing Authorization vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Exploiting Incorrectly Co...
CVE-2026-40740MEDIUM5.4Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control S...
CVE-2026-40737MEDIUM5.3Authorization Bypass Through User-Controlled Key vulnerability in VillaTheme COMPE compe-woo-compare-products allows Exp...
CVE-2026-40734MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zahlan Categories ...
CVE-2026-40730MEDIUM5.3Missing Authorization vulnerability in ThemeGrill ThemeGrill Demo Importer themegrill-demo-importer allows Exploiting In...
CVE-2026-40729MEDIUM4.3Missing Authorization vulnerability in bPlugins 3D viewer – Embed 3D Models 3d-viewer allows Exploiting Incorrectly Conf...
CVE-2026-40728MEDIUM4.3Missing Authorization vulnerability in BlockArt Magazine Blocks magazine-blocks allows Exploiting Incorrectly Configured...
CVE-2026-33805HIGH8.6@fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client's Connection head...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now