2026 CVE Vulnerabilities

66,985 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-3300CRITICAL9.8The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions...
CVE-2026-5115HIGH7.5The PaperCut NG/MF (specifically, the embedded application for Konica Minolta devices) is vulnerable to session hijackin...
CVE-2026-4794MEDIUM4.8Multiple cross-site scripting (XSS) vulnerabilities in PaperCut NG/MF before 25.0.10 allow authenticated administrator u...
CVE-2026-32734MEDIUM6.1baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has DOM-based cross-site scripting in tag ...
CVE-2026-30940HIGH7.2baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme ...
CVE-2026-30880CRITICAL9.8baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability ...
CVE-2026-30879MEDIUM6.1baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a cross-site scripting vulnerability i...
CVE-2026-30878MEDIUM5.3baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API allows unauthenticated...
CVE-2026-30877HIGH7.2baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in t...
CVE-2026-27697CRITICAL9.8baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a SQL injection vulnerability in blog ...
CVE-2026-21861HIGH7.2baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerabi...
CVE-2026-5157MEDIUM4.3A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected is an unknown function of the ...
CVE-2026-5156HIGH8.8A vulnerability was determined in Tenda CH22 1.0.0.1. This impacts the function formQuickIndex of the file /goform/Quick...
CVE-2026-5155HIGH8.8A vulnerability was found in Tenda CH22 1.0.0.1. This affects the function fromAdvSetWan of the file /goform/AdvSetWan o...
CVE-2026-5154HIGH8.8A vulnerability has been found in Tenda CH22 1.0.0.1/1.If. The impacted element is the function fromSetCfm of the file /...
CVE-2026-5130HIGH8.8The Debugger & Troubleshooter plugin for WordPress was vulnerable to Unauthenticated Privilege Escalation in versions up...
CVE-2026-5153HIGH8.8A flaw has been found in Tenda CH22 1.0.0.1. The affected element is the function FormWriteFacMac of the file /goform/Wr...
CVE-2026-4257CRITICAL9.8The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Rem...
CVE-2026-33995MEDIUM5.3FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a double-free vulnerability in...
CVE-2026-33987MEDIUM6.6FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in persistent_cache_read_entry...
CVE-2026-33986HIGH7.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in yuv_ensure_buffer() in libf...
CVE-2026-33985HIGH7.1FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap ...
CVE-2026-33984HIGH7.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libf...
CVE-2026-33983MEDIUM6.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, progressive_decompress_tile_up...
CVE-2026-33982HIGH8.1FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, there is a heap-buffer-overflo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now