2026 CVE Vulnerabilities

45,125 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-13347HIGH7.5The Hide My WP Lite plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 1.3 via th...
CVE-2026-12685HIGH7.5The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoor that let...
CVE-2026-21055HIGH8.5Improper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute a...
CVE-2026-21049HIGH8.4Out-of-bounds write in libpadm.so library prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary co...
CVE-2026-21048HIGH8.3Out-of-bounds write in parsing DNG format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote ...
CVE-2026-21046HIGH8.4Time-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privil...
CVE-2026-21045HIGH8.3Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote...
CVE-2026-21042HIGH8.4Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code.
CVE-2026-15330HIGH7.3A vulnerability was determined in zhayujie CowAgent up to 2.1.1. Impacted is the function _build_image_content/_download...
CVE-2026-15298HIGH7.2The TelSender plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting in all versions up to, and including,...
CVE-2026-15293HIGH8The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass in all versions up to, and ...
CVE-2026-15291HIGH7.5The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure in all ...
CVE-2026-15290HIGH7.5The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2026-15288HIGH7.5The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation...
CVE-2026-54423HIGH8.2In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface c...
CVE-2026-15070HIGH8.8The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
CVE-2026-13430HIGH7.2The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and...
CVE-2026-15319HIGH7.3A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. This affects the function IPAllowlist of the ...
CVE-2026-54771HIGH8.1Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.3, a Langroid appl...
CVE-2026-50181HIGH7.1Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, Langroid's `Rea...
CVE-2026-50180HIGH8.7Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, `SQLChatAgent` ...
CVE-2026-12598HIGH8.1The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via...
CVE-2026-12597HIGH8.1The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions...
CVE-2026-12595HIGH8.1The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all version...
CVE-2026-59858HIGH7.8Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/cco...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now