2026 CVE Vulnerabilities

68,768 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4258HIGH7.7Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to miss...
CVE-2026-4308MEDIUM6.3A weakness has been identified in frdel/agent0ai agent-zero 0.9.7. This affects the function handle_pdf_document of the ...
CVE-2026-4307MEDIUM4.3A security flaw has been discovered in frdel/agent0ai agent-zero 0.9.7-10. The impacted element is the function get_abs_...
CVE-2026-2373MEDIUM5.3The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Informatio...
CVE-2026-0708MEDIUM6.5A flaw was found in libucl. A remote attacker could exploit this by providing a specially crafted Universal Configuratio...
CVE-2026-2579HIGH7.5The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to SQL Injection via th...
CVE-2026-4289HIGH7.3A security vulnerability has been detected in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This affects an ...
CVE-2026-4288HIGH7.3A weakness has been identified in Tiandy Easy7 Integrated Management Platform 7.17.0. The impacted element is an unknown...
CVE-2026-4287HIGH7.3A security flaw has been discovered in Tiandy Easy7 Integrated Management Platform 7.17.0. The affected element is an un...
CVE-2026-4285LOW2.7A vulnerability was identified in taoofagi easegen-admin up to 8f87936ac774065b92fb20aab55b274a6ea76433. Impacted is the...
CVE-2026-4284MEDIUM4.7A vulnerability was determined in taoofagi easegen-admin up to 8f87936ac774065b92fb20aab55b274a6ea76433. This issue affe...
CVE-2026-4177CRITICAL9.1YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap ...
CVE-2026-21991MEDIUM5.5A DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names.
CVE-2026-2454HIGH8.6Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported array le...
CVE-2026-29522HIGH8.7ZwickRoell Test Data Management versions prior to 3.0.8 contain a local file inclusion (LFI) vulnerability in the /serve...
CVE-2026-26230LOW3.8Mattermost versions 10.11.x <= 10.11.10 fail to properly validate permission requirements in the team member roles API e...
CVE-2026-1629MEDIUM4.3Mattermost versions 10.11.x <= 10.11.10 Fail to invalidate cached permalink preview data when a user loses channel acces...
CVE-2026-32267CRITICAL9.8Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-R...
CVE-2026-32264HIGH7.2Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-R...
CVE-2026-32263HIGH7.2Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.11, in src/controllers/EntryTyp...
CVE-2026-32262MEDIUM4.3Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-R...
CVE-2026-30882MEDIUM6.1Chamilo LMS is a learning management system. Chamilo LMS version 1.11.34 and prior contains a Reflected Cross-Site Scrip...
CVE-2026-30881HIGH8.8Chamilo LMS is a learning management system. Version 1.11.34 and prior contains a SQL Injection vulnerability in the sta...
CVE-2026-30876MEDIUM5.3Chamilo LMS is a learning management system. Prior to version 1.11.36, Chamilo is vulnerable to user enumeration with va...
CVE-2026-30875HIGH8.8Chamilo LMS is a learning management system. Prior to version 1.11.36, an arbitrary file upload vulnerability in the H5P...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now