2026 CVE Vulnerabilities

70,017 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-2893MEDIUM6.5The Page and Post Clone plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' parameter in the content_...
CVE-2026-28552HIGH7.5Out-of-bounds write vulnerability in the IMS module. Impact: Successful exploitation of this vulnerability may affect av...
CVE-2026-28550MEDIUM4.7Race condition vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may a...
CVE-2026-28545MEDIUM4.7Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect av...
CVE-2026-28544MEDIUM4.7Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect av...
CVE-2026-28543MEDIUM4.7Race condition vulnerability in the maintenance and diagnostics module. Impact: Successful exploitation of this vulnerab...
CVE-2026-28541MEDIUM5.5Permission control vulnerability in the cellular_data module. Impact: Successful exploitation of this vulnerability may ...
CVE-2026-28540LOW3.3Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vulnerability may affec...
CVE-2026-28539MEDIUM5.5Data processing vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerabilit...
CVE-2026-28538MEDIUM5.5Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability...
CVE-2026-28537MEDIUM5.5Double free vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect availab...
CVE-2026-21786LOW3.3HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application...
CVE-2026-1321HIGH8.1The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up t...
CVE-2026-2743CRITICAL9.8Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected fea...
CVE-2026-28536HIGH8.1Authentication bypass vulnerability in the device authentication module. Impact: Successful exploitation of this vulnera...
CVE-2026-25702CRITICAL9.8A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5 breaks nftables, causi...
CVE-2026-1678CRITICAL9.8dns_unpack_name() caches the buffer tailroom once and reuses it while appending DNS labels. As the buffer grows, the cac...
CVE-2026-3072MEDIUM4.3The Media Library Assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap...
CVE-2026-30777MEDIUM6.5EC-CUBE provided by EC-CUBE CO.,LTD. contains a multi-factor authentication (MFA) bypass vulnerability. An attacker who ...
CVE-2026-2418CRITICAL9.1The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Sales...
CVE-2026-29128CRITICAL10IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zeb...
CVE-2026-29053CRITICAL9.8Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can ex...
CVE-2026-29052MEDIUM6.1The Calendar module for HumHub enables users to create one-time or recurring events, manage attendee invitations, and ef...
CVE-2026-28137HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs MediC...
CVE-2026-28135HIGH8.2Inclusion of Functionality from Untrusted Control Sphere vulnerability in WP Royal Royal Elementor Addons royal-elemento...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now