2026 CVE Vulnerabilities

70,363 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-1874HIGH7.5Always-Incorrect Control Flow Implementation vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENE...
CVE-2026-3455MEDIUM6.1Versions of the package mailparser before 3.9.3 are vulnerable to Cross-site Scripting (XSS) via the textToHtml() functi...
CVE-2026-3449LOW3.3Versions of the package @tootallnate/once before 3.0.1 are vulnerable to Incorrect Control Flow Scoping in promise resol...
CVE-2026-1492CRITICAL9.8The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restrict...
CVE-2026-20801MEDIUM5.6Cleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher ...
CVE-2026-20757LOW2.5Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited...
CVE-2026-2628CRITICAL9.8The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass...
CVE-2026-2448HIGH8.8The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc...
CVE-2026-2269HIGH7.2The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnera...
CVE-2026-1487MEDIUM6.5The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to SQL Injection ...
CVE-2026-0754HIGH8.2An embedded test key and certificate could be extracted from a Poly Voice device using specialized reverse engineering t...
CVE-2026-1566HIGH8.8The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to privilege esca...
CVE-2026-1336MEDIUM5.3The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access and m...
CVE-2026-2583MEDIUM6.4The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `blocksy_meta` metadata fields in a...
CVE-2026-3338HIGH8.7Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verificatio...
CVE-2026-3337HIGH8.2Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine au...
CVE-2026-3336HIGH8.7Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain v...
CVE-2026-2256MEDIUM6.5A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker t...
CVE-2026-27631MEDIUM5.3Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada...
CVE-2026-27596HIGH7.5Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada...
CVE-2026-26713CRITICAL9.8code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php.
CVE-2026-26712CRITICAL9.8code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php.
CVE-2026-25884HIGH8.1Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada...
CVE-2026-25477MEDIUM6.1AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.26.0, there is an Open Redire...
CVE-2026-21882HIGH8.4theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to versi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now