2026 CVE Vulnerabilities

46,943 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-56001HIGH8.8A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by...
CVE-2026-56000HIGH7.8Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland b...
CVE-2026-55999HIGH7.8Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland b...
CVE-2026-13129HIGH7.8When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in t...
CVE-2026-13128HIGH7.8Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the...
CVE-2026-13127HIGH7.8The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the...
CVE-2026-13126HIGH7.8The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a ...
CVE-2026-12378HIGH8.1The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data be...
CVE-2026-9700HIGH7.5The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up t...
CVE-2026-57895HIGH8.5Incorrect default permissions issue exists in Pupsman versions prior to 3.9.0. An attacker can place a malicious executa...
CVE-2026-56437HIGH8.4Uncontrolled search path element issue exists in Pupsman versions prior to 3.9.0. If a crafted DLL file is placed in the...
CVE-2026-14495HIGH8.8The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all vers...
CVE-2026-14489HIGH8.8The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the...
CVE-2026-9842HIGH7.5The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,...
CVE-2026-14482HIGH8.8The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. The v...
CVE-2026-14244HIGH7.5The Jssor Slider by jssor.com plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu...
CVE-2026-14158HIGH8.8The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including...
CVE-2026-60000HIGH7.5sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive au...
CVE-2026-59999HIGH7.5In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not...
CVE-2026-55436HIGH7.4Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and pr...
CVE-2026-55429HIGH8.7Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55428HIGH8.2Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55427HIGH8.3Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-59704HIGH7.1Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metada...
CVE-2026-55077HIGH7.2Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now