2026 CVE Vulnerabilities

65,328 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6111MEDIUM6.5A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.1. This impacts the function decode_image of t...
CVE-2026-6110CRITICAL9.8A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.1. This affects the function generate_thoughts of t...
CVE-2026-1116MEDIUM6.1A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in p...
CVE-2026-6109HIGH8.8A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The impacted element is the function evaluateCod...
CVE-2026-6108MEDIUM6.3A vulnerability was found in 1Panel-dev MaxKB up to 2.6.1. The affected element is the function execute of the file apps...
CVE-2026-6107MEDIUM5.1A flaw has been found in 1Panel-dev MaxKB up to 2.6.1. This issue affects some unknown processing of the file apps/commo...
CVE-2026-6106LOW3.5A vulnerability was detected in 1Panel-dev MaxKB up to 2.2.1. This vulnerability affects the function StaticHeadersMiddl...
CVE-2026-6105HIGH7.3A security vulnerability has been detected in perfree go-fastdfs-web up to 1.3.7. This affects an unknown part of the fi...
CVE-2026-31845CRITICAL9.3A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma ...
CVE-2026-32146HIGH7.8Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system...
CVE-2026-23900MEDIUM6.5Various stored XSS vulnerabilities in the maps- and icon rendering logic in Phoca Maps component 5.0.0-6.0.2 have been d...
CVE-2026-5809HIGH7.1The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. Th...
CVE-2026-34621HIGH8.6Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of ...
CVE-2026-5226MEDIUM6.1The Optimole – Optimize Images in Real Time plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL...
CVE-2026-5217HIGH7.2The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vuln...
CVE-2026-5207MEDIUM6.5The LifterLMS plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up to, and i...
CVE-2026-5144HIGH8.8The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including...
CVE-2026-4979MEDIUM5The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre...
CVE-2026-4895MEDIUM6.4The GreenShift - Animation and Page Builder Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ...
CVE-2026-3498MEDIUM6.4The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clientId' block attribute...
CVE-2026-3371MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere...
CVE-2026-3358MEDIUM5.4The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized private course e...
CVE-2026-5496HIGH7.8Labcenter Electronics Proteus PDSPRJ File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability...
CVE-2026-5495HIGH7.8Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerab...
CVE-2026-5494HIGH7.8Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerab...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now