2026 CVE Vulnerabilities

45,220 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-7655HIGH8.1The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and incl...
CVE-2026-13378HIGH7.2The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contac...
CVE-2026-3576HIGH7.2The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local ...
CVE-2026-2354HIGH8.8The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validatio...
CVE-2026-15335HIGH7.5The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in ...
CVE-2026-14262HIGH8.8The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Byp...
CVE-2026-15338HIGH7.5The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to...
CVE-2026-13353HIGH8.8The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remo...
CVE-2026-13114HIGH7.2The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2026-13756HIGH8.8The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3...
CVE-2026-55175HIGH7.5Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, a...
CVE-2026-44383HIGH8.7Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to de...
CVE-2026-42952HIGH8.7Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could al...
CVE-2026-57584HIGH8.7Phalcon is a high-performance, full-stack PHP framework. Prior to 5.15.0, every Phalcon MVC application built with a def...
CVE-2026-55883HIGH8.3Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.24.0 through 0.37.3, the Tilt HUD WebS...
CVE-2026-55882HIGH8.3Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.19.5 through 0.37.3, the Tilt HUD serv...
CVE-2026-55852HIGH8.6Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, TarSlip RCE was possible in Package Imp...
CVE-2026-55810HIGH8.1Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphin...
CVE-2026-55809HIGH8.1Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance f...
CVE-2026-54736HIGH8.2Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::decrypt compares the...
CVE-2026-52747HIGH8.6ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to ...
CVE-2026-49394HIGH7.1Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_pag...
CVE-2026-49213HIGH8.1TypeBot is a chatbot builder tool. Prior to 3.17.2, Typebot's shared SSRF validator in packages/lib/src/ssrf/validateHtt...
CVE-2026-44795HIGH8.8Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3...
CVE-2026-41482HIGH7.1Frappe is a full-stack web application framework. Prior to 16.18.3, possible path traversal and local file inclusion wer...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now