2026 CVE Vulnerabilities

68,833 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-20991MEDIUM4.4Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse...
CVE-2026-20990HIGH8.1Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attacker...
CVE-2026-20989LOW2.4Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attack...
CVE-2026-20988MEDIUM5Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker ...
CVE-2026-1948MEDIUM4.3The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of d...
CVE-2026-1947HIGH7.5The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Referen...
CVE-2026-1883MEDIUM4.3The Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress is vulnerable to Inse...
CVE-2026-1870MEDIUM5.3The Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor plugin for WordPress is vulnerable to unauthori...
CVE-2026-0977HIGH7.1IBM CICS Transaction Gateway for Multiplatforms 9.3 and 10.1 could allow a user to transfer or view files due to imprope...
CVE-2026-0849MEDIUM6.8Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver...
CVE-2026-0639MEDIUM5.5in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory.
CVE-2026-0385MEDIUM5Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2026-4111HIGH7.5A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive...
CVE-2026-4105MEDIUM6.7A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insuf...
CVE-2026-4092HIGH8.8Path Traversal in Clasp impacting versions < 3.2.0 allows a remote attacker to perform remote code execution via a malic...
CVE-2026-4063MEDIUM4.3The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized data modification due to a ...
CVE-2026-3999HIGH8.8A broken access control may allow an authenticated user to perform a horizontal privilege escalation. The vulnerability...
CVE-2026-3986MEDIUM6.4The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form settings in al...
CVE-2026-3910HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrar...
CVE-2026-3909HIGH8.8Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds m...
CVE-2026-3891CRITICAL9.8The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and...
CVE-2026-3873HIGH7.2Use of Hard-coded Credentials vulnerability in Avantra allows Accessing Functionality Not Properly Constrained by ACLs....
CVE-2026-3045HIGH7.5The Appointment Booking Calendar — Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized acces...
CVE-2026-32746CRITICAL9.8telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption ...
CVE-2026-32745MEDIUM5.7In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now