2026 CVE Vulnerabilities

67,295 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-87909HIGH7.5The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_m...
CVE-2026-84434CRITICAL9.8The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1....
CVE-2026-15760MEDIUM6.5The Divi Essential plugin for WordPress is vulnerable to sensitive information exposure in versions up to, and including...
CVE-2026-15660MEDIUM4.3The SEO Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.4.7. Thi...
CVE-2026-13354HIGH7.2The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Cont...
CVE-2026-12042MEDIUM4.4The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v...
CVE-2026-77820MEDIUM6.4The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'empty' Shortcode Attribute in all ...
CVE-2026-93923HIGH8.8SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing st...
CVE-2026-93922HIGH8.8SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing store...
CVE-2026-93921MEDIUM4.3SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only ...
CVE-2026-77875MEDIUM6.8The application protects access through its calculator-style vault passcode, but the stored data is not bound to that au...
CVE-2026-93740CRITICAL10A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file...
CVE-2026-93739CRITICAL9.9A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /bo...
CVE-2026-75885CRITICAL9.3A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` end...
CVE-2026-93894LOW2.3In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type ...
CVE-2026-93738CRITICAL9.9A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boa...
CVE-2026-93574MEDIUM6.5A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending ...
CVE-2026-93562MEDIUM6.5A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote...
CVE-2026-88097HIGH7.8Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.
CVE-2026-85272MEDIUM4.3Open edX Platform enables the authoring and delivery of online learning at any scale. From Aspen.1 until Ulmo and Verawo...
CVE-2026-85271MEDIUM6.1Open edX Platform enables the authoring and delivery of online learning at any scale. From Redwood until Ulmo and Verawo...
CVE-2026-71855HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2026-71418HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr...
CVE-2026-68928HIGH8.6Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.Term...
CVE-2026-63452HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now