2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-18468HIGH8.1The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the acc...
CVE-2026-18030HIGH8.1The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password...
CVE-2026-17542HIGH7.5The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connecto...
CVE-2026-17541HIGH7.5The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowin...
CVE-2026-17540HIGH8.8The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any au...
CVE-2026-17022HIGH7.5The Salon Booking System WordPress plugin through 10.30.33 does not properly validate a booking's ownership token befor...
CVE-2026-16985HIGH8.8The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data writ...
CVE-2026-16257HIGH8.2The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, wh...
CVE-2026-14293HIGH8.8The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option ...
CVE-2026-14237HIGH7.2The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorizat...
CVE-2026-14206HIGH7.5The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns...
CVE-2026-13600HIGH8.1The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before settin...
CVE-2026-13170HIGH7.2The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to includ...
CVE-2026-13133HIGH8.4A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is lo...
CVE-2026-19389HIGH7.1Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdem...
CVE-2026-19387HIGH7.6A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/D...
CVE-2026-19384HIGH7.3A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unkno...
CVE-2026-19381HIGH7.8A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unkn...
CVE-2026-19379HIGH7.3A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of t...
CVE-2026-19376HIGH7.3A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class o...
CVE-2026-19374HIGH7.3A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affect...
CVE-2026-19355HIGH7.3A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of...
CVE-2026-19351HIGH7.3A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the ...
CVE-2026-19346HIGH8.8A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the fi...
CVE-2026-19344HIGH7.3A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown funct...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now