2026 CVE Vulnerabilities

45,428 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-54801HIGH8.6A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst...
CVE-2026-54799HIGH8.4A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst...
CVE-2026-54798HIGH7.1A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst...
CVE-2026-4256HIGH8.2Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology ...
CVE-2026-12593HIGH8.7The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to en...
CVE-2026-9253HIGH7.2The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scrip...
CVE-2026-59692HIGH7.5A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificat...
CVE-2026-59691HIGH7.1A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/V...
CVE-2026-50644HIGH8.6SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all right...
CVE-2026-4275HIGH8.8The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request F...
CVE-2026-14372HIGH7.1The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is v...
CVE-2026-13441HIGH7.2The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2026-56458HIGH7.5HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged action...
CVE-2026-1989HIGH7.5Authorization bypass through User-Controlled key vulnerability in PAVO Financial Technology Solutions Inc. PAVO Pay allo...
CVE-2026-8848HIGH7.2The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress ...
CVE-2026-57111HIGH7.5Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFi...
CVE-2026-33390HIGH8.1An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors r...
CVE-2026-31985HIGH8.3When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disab...
CVE-2026-31984HIGH8.7A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functional...
CVE-2026-31982HIGH7.1An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of...
CVE-2026-15000HIGH7.2The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mailchimp...
CVE-2026-47831HIGH7.7Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-...
CVE-2026-47830HIGH8.8Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege ...
CVE-2026-47829HIGH7.8Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-s...
CVE-2026-47828HIGH8.8During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now