2026 CVE Vulnerabilities

68,850 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-0977HIGH7.1IBM CICS Transaction Gateway for Multiplatforms 9.3 and 10.1 could allow a user to transfer or view files due to imprope...
CVE-2026-0849MEDIUM6.8Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver...
CVE-2026-0639MEDIUM5.5in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory.
CVE-2026-0385MEDIUM5Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2026-4111HIGH7.5A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive...
CVE-2026-4105MEDIUM6.7A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insuf...
CVE-2026-4092HIGH8.8Path Traversal in Clasp impacting versions < 3.2.0 allows a remote attacker to perform remote code execution via a malic...
CVE-2026-4063MEDIUM4.3The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized data modification due to a ...
CVE-2026-3999HIGH8.8A broken access control may allow an authenticated user to perform a horizontal privilege escalation. The vulnerability...
CVE-2026-3986MEDIUM6.4The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form settings in al...
CVE-2026-3910HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrar...
CVE-2026-3909HIGH8.8Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds m...
CVE-2026-3891CRITICAL9.8The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and...
CVE-2026-3873HIGH7.2Use of Hard-coded Credentials vulnerability in Avantra allows Accessing Functionality Not Properly Constrained by ACLs....
CVE-2026-3045HIGH7.5The Appointment Booking Calendar — Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized acces...
CVE-2026-32746CRITICAL9.8telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption ...
CVE-2026-32745MEDIUM5.7In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings
CVE-2026-32612MEDIUM5.4Statamic is a Laravel and Git powered content management system (CMS). Prior to 6.6.2, stored XSS in the control panel c...
CVE-2026-32598MEDIUM6.5OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the ...
CVE-2026-32597HIGH7.5PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header ...
CVE-2026-32543MEDIUM5.3Missing Authorization vulnerability in CyberChimps Responsive Blocks responsive-block-editor-addons allows Exploiting In...
CVE-2026-32487MEDIUM5.3Missing Authorization vulnerability in raratheme Lawyer Landing Page lawyer-landing-page allows Exploiting Incorrectly C...
CVE-2026-32486MEDIUM5.3Missing Authorization vulnerability in wptravelengine Travel Booking travel-booking allows Exploiting Incorrectly Config...
CVE-2026-32462MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Maste...
CVE-2026-32461MEDIUM4.3Missing Authorization vulnerability in Really Simple Plugins Really Simple SSL really-simple-ssl allows Exploiting Incor...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now