2026 CVE Vulnerabilities

46,868 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-15190HIGH7.3A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown part of...
CVE-2026-13462HIGH7.5PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to ...
CVE-2026-59206HIGH7.1n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated user with t...
CVE-2026-11404HIGH8.7Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello...
CVE-2026-60109HIGH8.7Zeek before 8.0.9 contains a null pointer dereference vulnerability in its Kerberos protocol analyzer that allows unauth...
CVE-2026-60108HIGH8.7Zeek before 8.0.9 contains an uncontrolled memory consumption vulnerability in the FTP analyzer that allows unauthentica...
CVE-2026-56292HIGH7.5Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 10.11.1 - A SQLi vulnerability in AcyMailing...
CVE-2026-54801HIGH8.6A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst...
CVE-2026-54799HIGH8.4A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst...
CVE-2026-54798HIGH7.1A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst...
CVE-2026-4256HIGH8.2Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology ...
CVE-2026-12593HIGH8.7The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to en...
CVE-2026-9253HIGH7.2The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scrip...
CVE-2026-59692HIGH7.5A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificat...
CVE-2026-59691HIGH7.1A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/V...
CVE-2026-50644HIGH8.6SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all right...
CVE-2026-4275HIGH8.8The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request F...
CVE-2026-14372HIGH7.1The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is v...
CVE-2026-13441HIGH7.2The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2026-56458HIGH7.5HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged action...
CVE-2026-1989HIGH7.5Authorization bypass through User-Controlled key vulnerability in PAVO Financial Technology Solutions Inc. PAVO Pay allo...
CVE-2026-8848HIGH7.2The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress ...
CVE-2026-57111HIGH7.5Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFi...
CVE-2026-33390HIGH8.1An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors r...
CVE-2026-31985HIGH8.3When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disab...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now