2026 CVE Vulnerabilities

65,063 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-30778HIGH7.5The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL. Th...
CVE-2026-28741HIGH8.1Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to validate CSRF toke...
CVE-2026-27769LOW2.7Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Wor...
CVE-2026-5598HIGH7.5Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulne...
CVE-2026-5588HIGH7.5Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all...
CVE-2026-3505HIGH7.5Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the B...
CVE-2026-33808CRITICAL9.1Impact@fastify/express v4.0.4 and earlier fails to normalize URLs before passing them to Express middleware when Fastify...
CVE-2026-33807CRITICAL9.1@fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths...
CVE-2026-0636MEDIUM6.5Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Boun...
CVE-2026-5717MEDIUM6.4The VI: Include Post By plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_container' attr...
CVE-2026-5694HIGH7.2The Quick Interest Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'loan-amount' and 'l...
CVE-2026-5617HIGH8.8The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3...
CVE-2026-4091MEDIUM6.1The OPEN-BRAIN plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0....
CVE-2026-4011MEDIUM6.4The Power Charts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [p...
CVE-2026-4005MEDIUM6.4The Coachific Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userhash' shortcode a...
CVE-2026-4002MEDIUM4.3The Petje.af plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 2.1.8....
CVE-2026-3998MEDIUM6.4The WM JqMath plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' shortcode attribute of t...
CVE-2026-3659MEDIUM6.4The WP Circliful plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of t...
CVE-2026-3649MEDIUM5.3The Katalogportal PDF Sync plugin for WordPress is vulnerable to Missing Authorization in all versions up to and includi...
CVE-2026-3643HIGH7.2The Accessibly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in all versions up to,...
CVE-2026-3642MEDIUM5.3The e-shot™ form builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including...
CVE-2026-3461CRITICAL9.8The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and inc...
CVE-2026-1782MEDIUM5.3The MetForm Pro plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 3...
CVE-2026-5088HIGH7.5Apache::API::Password versions through 0.5.2 for Perl can generate insecure random values for salts. The _make_salt and...
CVE-2026-6293MEDIUM4.3The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now