2026 CVE Vulnerabilities

67,727 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-54645MEDIUM4.8CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, ...
CVE-2026-54644MEDIUM6.1CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip...
CVE-2026-54643MEDIUM5.4CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete-note handler in admin/sources/orders.index.inc.ph...
CVE-2026-54642MEDIUM5.3CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored-...
CVE-2026-54634HIGH7.3Hamlib is a ham radio control library for radios, rotators, and amplifiers. Prior to 4.7.2, the unauthenticated rigctld ...
CVE-2026-54633MEDIUM6.9PoDoFo is a C++17 PDF manipulation library. From version 1.0.0 until 1.1.1, processing a crafted PDF with an Indexed col...
CVE-2026-54613MEDIUM5.4Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5...
CVE-2026-54612HIGH8.8Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 until...
CVE-2026-54608HIGH7.1MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier, GET /api/stripe/process in backend/app/Api/Syste...
CVE-2026-54520HIGH8.1AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior ...
CVE-2026-54519HIGH8.8AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior ...
CVE-2026-54507HIGH8.4Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5...
CVE-2026-54506HIGH7.6Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5...
CVE-2026-54343HIGH8.7Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version ...
CVE-2026-53557HIGH7.7SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated use...
CVE-2026-53556MEDIUM6SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/dat...
CVE-2026-53555MEDIUM5.1SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated upl...
CVE-2026-53554HIGH7.3SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/dat...
CVE-2026-53534HIGH7.5JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. Prior to 6.0-alpha.6, when jabsrv or JabRef'...
CVE-2026-50291MEDIUM5.5OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a...
CVE-2026-50158HIGH7.7yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool ...
CVE-2026-16750MEDIUM5.3The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of da...
CVE-2026-16582MEDIUM5.3The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modificatio...
CVE-2026-14311MEDIUM5.4The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and ...
CVE-2026-11432——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now