2026 CVE Vulnerabilities

46,942 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-6820HIGH7.2The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ema...
CVE-2026-5356HIGH7.5The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input...
CVE-2026-6854HIGH7.5The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the ...
CVE-2026-6818HIGH7.2The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'spe...
CVE-2026-6230HIGH7.5The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all ve...
CVE-2026-3688HIGH8.1The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure...
CVE-2026-56003HIGH8.8A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeSc...
CVE-2026-56002HIGH8.8A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers auth...
CVE-2026-57260HIGH7.8The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly re...
CVE-2026-57256HIGH7.8When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and thi...
CVE-2026-57254HIGH7.8There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF,...
CVE-2026-57252HIGH7.8When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotatio...
CVE-2026-57251HIGH7.8The application opens a PDF, but the cloud-like appearance of the construction process lacks proper setting of an upper ...
CVE-2026-57250HIGH7.8When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlyi...
CVE-2026-57249HIGH7.8After the application opened the PDF file, the script first reset the annotation status, then triggered the reset form e...
CVE-2026-57248HIGH7.8When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object ...
CVE-2026-57247HIGH7.8The application re-enters the document structure via field processing and deletes the current page, and then continues u...
CVE-2026-57246HIGH7.8When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature ...
CVE-2026-57245HIGH7.8When the application opens a PDF, traverses and builds the annotation elements related to hyperlinks, it fails to valida...
CVE-2026-57244HIGH7.8After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verifica...
CVE-2026-57242HIGH7.8The application opens the PDF, and JavaScript modifies the form. However, the related objects on the page lack complete ...
CVE-2026-57240HIGH7.8When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old fie...
CVE-2026-57239HIGH7.8The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege use...
CVE-2026-57238HIGH7.8After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the...
CVE-2026-57237HIGH7.8When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the under...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now