2026 CVE Vulnerabilities

67,237 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4615HIGH7.3A vulnerability was identified in SourceCodester Online Catering Reservation 1.0. Impacted is an unknown function of the...
CVE-2026-4614MEDIUM6.3A vulnerability was determined in itsourcecode sanitize or validate this input 1.0. This issue affects some unknown proc...
CVE-2026-4613HIGH7.3A vulnerability was found in SourceCodester E-Commerce Site 1.0. This vulnerability affects unknown code of the file /pr...
CVE-2026-4056MEDIUM5.4The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a miss...
CVE-2026-4021HIGH8.1The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in ...
CVE-2026-4001CRITICAL9.8The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up...
CVE-2026-3533HIGH8.8The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_pop...
CVE-2026-33286CRITICAL9.1Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. Versions prior t...
CVE-2026-33283HIGH7.5Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing malformed UL NAS Tra...
CVE-2026-33282HIGH7.5Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing a malformed NGAP Loc...
CVE-2026-33281HIGH7.5Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing NGAP messages with i...
CVE-2026-33252MEDIUM6.5The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.1, the Go SDK's Streamable HTTP transport accepted...
CVE-2026-33250HIGH7.5Freeciv21 is a free open source, turn-based, empire-building strategy game. Versions prior to 3.1.1 crash with a stack o...
CVE-2026-33242HIGH7.5Salvo is a Rust web framework. Versions 0.39.0 through 0.89.2 have a Path Traversal and Access Control Bypass vulnerabil...
CVE-2026-33241HIGH7.5Salvo is a Rust web framework. Prior to version 0.89.3, Salvo's form data parsing implementations (`form_data()` method ...
CVE-2026-33211CRITICAL9.6Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and...
CVE-2026-33202CRITICAL9.1Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a...
CVE-2026-33195CRITICAL9.8Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a...
CVE-2026-33176HIGH7.5Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to v...
CVE-2026-33174HIGH7.5Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a...
CVE-2026-33173MEDIUM5.3Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a...
CVE-2026-33170MEDIUM6.1Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to v...
CVE-2026-33169MEDIUM5.3Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. `NumberToD...
CVE-2026-4306HIGH7.5The WP Job Portal plugin for WordPress is vulnerable to SQL Injection via the 'radius' parameter in all versions up to, ...
CVE-2026-4066MEDIUM4.3The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now