2026 CVE Vulnerabilities

65,279 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-1852MEDIUM6.1The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u...
CVE-2026-40786MEDIUM4.3Missing Authorization vulnerability in Long Watch Studio MyRewards woorewards allows Exploiting Incorrectly Configured A...
CVE-2026-40784HIGH8.1Authorization Bypass Through User-Controlled Key vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows ...
CVE-2026-40778MEDIUM5.3Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly ...
CVE-2026-40764HIGH8.1Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Cross Site Re...
CVE-2026-40763MEDIUM5.3Missing Authorization vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrec...
CVE-2026-40745HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bdthemes Element P...
CVE-2026-40744HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beaver Builder Bea...
CVE-2026-40742MEDIUM5.3Missing Authorization vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Exploiting Incorrectly Co...
CVE-2026-40740MEDIUM5.4Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control S...
CVE-2026-40737MEDIUM5.3Authorization Bypass Through User-Controlled Key vulnerability in VillaTheme COMPE compe-woo-compare-products allows Exp...
CVE-2026-40734MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zahlan Categories ...
CVE-2026-40730MEDIUM5.3Missing Authorization vulnerability in ThemeGrill ThemeGrill Demo Importer themegrill-demo-importer allows Exploiting In...
CVE-2026-40729MEDIUM4.3Missing Authorization vulnerability in bPlugins 3D viewer – Embed 3D Models 3d-viewer allows Exploiting Incorrectly Conf...
CVE-2026-40728MEDIUM4.3Missing Authorization vulnerability in BlockArt Magazine Blocks magazine-blocks allows Exploiting Incorrectly Configured...
CVE-2026-33805HIGH8.6@fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client's Connection head...
CVE-2026-30778HIGH7.5The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL. Th...
CVE-2026-28741HIGH8.1Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to validate CSRF toke...
CVE-2026-27769LOW2.7Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Wor...
CVE-2026-5598HIGH7.5Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulne...
CVE-2026-5588HIGH7.5Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all...
CVE-2026-3505HIGH7.5Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the B...
CVE-2026-33808CRITICAL9.1Impact@fastify/express v4.0.4 and earlier fails to normalize URLs before passing them to Express middleware when Fastify...
CVE-2026-33807CRITICAL9.1@fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths...
CVE-2026-0636MEDIUM6.5Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Boun...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now