2026 CVE Vulnerabilities

67,095 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5004HIGH8.8A vulnerability was determined in Wavlink WL-WN579X3-C 231124. This impacts the function sub_4019FC of the file /cgi-bin...
CVE-2026-5003MEDIUM5.5A vulnerability was found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. This affects the fun...
CVE-2026-5002HIGH7.3A vulnerability has been found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. The impacted el...
CVE-2026-5001HIGH7.3A flaw has been found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. The affected element is ...
CVE-2026-5000HIGH7.3A vulnerability was detected in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. Impacted is the f...
CVE-2026-4999MEDIUM6.3A security vulnerability has been detected in z-9527 admin up to 72aaf2dd05cf4ec2e98f390668b41e128eec5ad2. This issue af...
CVE-2026-4998HIGH7.3A weakness has been identified in Sinaptik AI PandasAI up to 3.0.0. This vulnerability affects the function CodeExecutor...
CVE-2026-4997MEDIUM5.5A security flaw has been discovered in Sinaptik AI PandasAI up to 3.0.0. This affects the function is_sql_query_safe of ...
CVE-2026-4996HIGH7.3A vulnerability was identified in Sinaptik AI PandasAI up to 0.1.4. Affected by this issue is the function delete_questi...
CVE-2026-2595MEDIUM5.4The Quads Ads Manager for Google AdSense plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u...
CVE-2026-4995LOW3.5A vulnerability was determined in wandb OpenUI up to 1.0. Affected by this vulnerability is an unknown functionality of ...
CVE-2026-4994LOW3.5A vulnerability was found in wandb OpenUI up to 1.0/3.5-turb. Affected is the function generic_exception_handler of the ...
CVE-2026-4993LOW3.3A vulnerability has been found in wandb OpenUI up to 0.0.0.0/1.0. This impacts an unknown function of the file backend/o...
CVE-2026-2442MEDIUM5.3The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Improper Neutralizatio...
CVE-2026-23399MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nf_tables: nft_dynset: fix possible stateful expres...
CVE-2026-1307MEDIUM6.5The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Informati...
CVE-2026-4987HIGH7.5The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Payment Amo...
CVE-2026-1679HIGH7.8The eswifi socket offload driver copies user-provided payloads into a fixed buffer without checking available space; ove...
CVE-2026-4992MEDIUM4.3A flaw has been found in wandb OpenUI up to 1.0. This affects the function create_share/get_share of the file backend/op...
CVE-2026-4991MEDIUM5.1A vulnerability was detected in QDOCS Smart School Management System up to 7.2. The impacted element is an unknown funct...
CVE-2026-4248HIGH8The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl...
CVE-2026-33996MEDIUM5.5LibJWT is a C JSON Web Token Library. Starting in version 3.0.0 and prior to version 3.3.0, the JWK parsing for RSA-PSS ...
CVE-2026-33994CRITICAL9.8Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Starting in version 2.0.39...
CVE-2026-33993CRITICAL9.8Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.25, t...
CVE-2026-33992MEDIUM6.5pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, PyLoad's download e...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now