2026 CVE Vulnerabilities

47,538 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-10054HIGH8.8In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSoc...
CVE-2026-47896HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucen...
CVE-2026-9148HIGH7.2The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Websi...
CVE-2026-47897HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucen...
CVE-2026-9547HIGH7.4When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION`...
CVE-2026-9546HIGH7.5A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the document...
CVE-2026-9545HIGH7.5In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transf...
CVE-2026-9080HIGH7.3Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerab...
CVE-2026-8932HIGH7.5libcurl would reuse a previously created connection even when some mTLS config related option had been changed that shou...
CVE-2026-8286HIGH8.1A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live co...
CVE-2026-4967HIGH7.5In IMS, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of servic...
CVE-2026-12064HIGH7.5When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs betwe...
CVE-2026-11586HIGH7.5By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation...
CVE-2026-11352HIGH7.5An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service agai...
CVE-2026-14352HIGH7.5The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8...
CVE-2026-13040HIGH7.2The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2026-8921HIGH8.5External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary co...
CVE-2026-14327HIGH7.5The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.4...
CVE-2026-8247HIGH8.8An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local n...
CVE-2026-13722HIGH7.2WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore featu...
CVE-2026-13384HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged u...
CVE-2026-13383HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged ...
CVE-2026-13368HIGH8.1WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for th...
CVE-2026-13084HIGH7.5A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create...
CVE-2026-13079HIGH7.8A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attac...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now