2026 CVE Vulnerabilities

65,293 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-31924MEDIUM5.3Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plain...
CVE-2026-31923HIGH7.5Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in o...
CVE-2026-31908CRITICAL9.1Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-au...
CVE-2026-27668HIGH8.8A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8). U...
CVE-2026-25654HIGH8.8A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate u...
CVE-2026-24032HIGH7.3A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC). The affected application contains a...
CVE-2026-2582MEDIUM6.5The The Germanized for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution via 'account_hold...
CVE-2026-3017HIGH7.2The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to P...
CVE-2026-4479MEDIUM4.4The WholeSale Products Dynamic Pricing Management WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2026-4059MEDIUM6.4The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the woolentor_quickview_button shor...
CVE-2026-40315CRITICAL9.8PraisonAI is a multi-agent teams system. Prior to 4.5.133, there is an SQL identifier injection vulnerability in SQLiteC...
CVE-2026-40313CRITICAL9.1PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to A...
CVE-2026-40289CRITICAL9.1PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the brow...
CVE-2026-40288CRITICAL9.8PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the work...
CVE-2026-40287HIGH8.4PraisonAI is a multi-agent teams system. Versions 4.5.138 and below are vulnerable to arbitrary code execution through a...
CVE-2026-1607MEDIUM6.4The Surbma | Booking.com Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `s...
CVE-2026-6264CRITICAL9.8A critical vulnerability in the Talend JobServer and Talend Runtime allows unauthenticated remote code execution via the...
CVE-2026-6227HIGH7.2The BackWPup plugin for WordPress is vulnerable to Local File Inclusion via the `block_name` parameter of the `/wp-json/...
CVE-2026-4388HIGH7.2The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box...
CVE-2026-34984MEDIUM6.5External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete...
CVE-2026-4365CRITICAL9.1The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the...
CVE-2026-4352HIGH7.5The JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endp...
CVE-2026-39426MEDIUM5.4MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS...
CVE-2026-39425MEDIUM5.4MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS...
CVE-2026-39419LOW3.1MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, an authenticated user can bypass sandb...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now