2026 CVE Vulnerabilities

67,276 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-82560HIGH7.5Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting d...
CVE-2026-94001MEDIUM6.5A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint...
CVE-2026-94000MEDIUM6.6A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue oc...
CVE-2026-93999MEDIUM4.2A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution...
CVE-2026-93987LOW3.4rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin....
CVE-2026-93986LOW3.1rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allow...
CVE-2026-93985CRITICAL9.9OpenPanel js-runtime through 2.3.0 contains a sandbox escape vulnerability in the JavaScript webhook template validator ...
CVE-2026-93984MEDIUM5.3OpenPanel tracking API through 2.3.0 fails to verify client secret cryptographic hash before authorizing revenue events ...
CVE-2026-93983MEDIUM5OpenPanel through 2.3.0 fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject ...
CVE-2026-93982LOW3.3OpenPanel through 2.3.0 writes Model Context Protocol authentication tokens from URL query parameters to plaintext appli...
CVE-2026-93981MEDIUM4.7hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a stri...
CVE-2026-78030CRITICAL9.8DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM....
CVE-2026-9858MEDIUM4.3The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and ...
CVE-2026-9766MEDIUM4.3The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin...
CVE-2026-9613MEDIUM4.3The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all version...
CVE-2026-9289MEDIUM5.3The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi...
CVE-2026-93742CRITICAL9.9A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of ...
CVE-2026-8354MEDIUM6.4The Gum Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pop_tag' paramete...
CVE-2026-76579MEDIUM4.7The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all ...
CVE-2026-5410MEDIUM6.4The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions ...
CVE-2026-1256MEDIUM6.4The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple A...
CVE-2026-1255HIGH7.5The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including...
CVE-2026-18346MEDIUM5.3The TikTok plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.1. This ...
CVE-2026-9855MEDIUM6.5The Custom Field Template plugin for WordPress is vulnerable to generic SQL Injection via the 'post_ID' parameter in all...
CVE-2026-9832MEDIUM5.3The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptograph...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now