2026 CVE Vulnerabilities

64,760 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-94176HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 versions.
CVE-2026-94174HIGH7.6Administrator SQL Injection in Email Log <= 2.63 versions.
CVE-2026-94124HIGH8.5Contributor SQL Injection in WP EasyCart <= 5.9.4 versions.
CVE-2026-93774HIGH7.1Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions.
CVE-2026-93773HIGH8.5Contributor SQL Injection in Mollie Forms <= 2.11.0 versions.
CVE-2026-93622HIGH7.1Unauthenticated Cross Site Scripting (XSS) in WPS Limit Login <= 1.5.9.3 versions.
CVE-2026-93527HIGH8.5Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions.
CVE-2026-93526HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions.
CVE-2026-92730HIGH7.4LimeSurvey Community Edition 7.0.14 contains a reflected cross-site scripting vulnerability on the administrative survey...
CVE-2026-90905HIGH7.2Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension...
CVE-2026-90904HIGH8.6Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store ext...
CVE-2026-90903HIGH7.2Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Stor...
CVE-2026-90902HIGH8.6Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extensio...
CVE-2026-90901HIGH8.6Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extens...
CVE-2026-90899HIGH8.2Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0....
CVE-2026-84499HIGH7.7A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are ...
CVE-2026-84486HIGH8.2A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views that trigger the inte...
CVE-2026-82368HIGH8.7Insecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow local, non-administrat...
CVE-2026-82356HIGH7.5Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key pair after deployment when generating an X.509 certificat...
CVE-2026-77601HIGH8.8OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2026-77423HIGH7.5JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in less viewer p...
CVE-2026-77422HIGH7.5JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in grep command ...
CVE-2026-77394HIGH7.6OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2026-76648HIGH8.5CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs n...
CVE-2026-76089HIGH7.7Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-rese...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now