2026 CVE Vulnerabilities

65,654 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-2988MEDIUM6.4The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'powerpress' and 'podca...
CVE-2026-5726HIGH8.4ASDA-Soft Stack-based Buffer Overflow Vulnerability
CVE-2026-1163MEDIUM4.1An insufficient session expiration vulnerability exists in the latest version of parisneo/lollms. The application fails ...
CVE-2026-3499HIGH8.8The Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce plugin for WordPress is vulnerable to C...
CVE-2026-3296CRITICAL9.8The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3...
CVE-2026-33810HIGH8.2When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to w...
CVE-2026-32289MEDIUM6.1Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escapi...
CVE-2026-32288MEDIUM5.5tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large numb...
CVE-2026-32283HIGH7.5If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection c...
CVE-2026-32282MEDIUM6.4On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can ope...
CVE-2026-32281HIGH7.5Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a ve...
CVE-2026-32280HIGH7.5During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cert...
CVE-2026-27144HIGH7.1The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented...
CVE-2026-27143CRITICAL9.8Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the comp...
CVE-2026-27140HIGH8.8SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at ...
CVE-2026-4788MEDIUM5.5IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.37 stores sensitive information in log files that could be read by a loc...
CVE-2026-3357HIGH8.8IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the sys...
CVE-2026-1346HIGH7.8IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ...
CVE-2026-1343HIGH7.2IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ...
CVE-2026-5747HIGH8.7An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and a...
CVE-2026-4406MEDIUM4.7The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in t...
CVE-2026-4401MEDIUM5.4The Download Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in the `actions_handler()` and `bu...
CVE-2026-4394MEDIUM6.1The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Credit Card field's 'Card Ty...
CVE-2026-2263MEDIUM5.3The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized modific...
CVE-2026-1342HIGH7.9IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now