2026 CVE Vulnerabilities

47,686 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-53903HIGH8.1MCO is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability in the /customer/servlet/mco/webapi/tradin...
CVE-2026-14181HIGH7.5@fastify/middie versions 9.1.0 through 9.3.2 fail to guard the URL normalization step used by the standalone engine when...
CVE-2026-13323HIGH8.7In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/h...
CVE-2026-13228HIGH8.8The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Esca...
CVE-2026-12142HIGH7.2The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2026-50043HIGH8.6Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge MB-...
CVE-2026-12577HIGH8.7DVP80ES3 with Improperly Implemented Security Check for Standard vulnerability.
CVE-2026-12576HIGH7.5DVP80ES3 with Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability.
CVE-2026-12575HIGH7.5DVP80ES3 with  Improper Resource Shutdown or Release vulnerability.
CVE-2026-12224HIGH8.8The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all ve...
CVE-2026-12158HIGH8.8The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery ...
CVE-2026-10538HIGH8.9Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowe...
CVE-2026-1239HIGH7.5The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access...
CVE-2026-14193HIGH7.5DVP80ES300T with Improper Validation of Array Index Vulnerability
CVE-2026-12579HIGH7.4AS228T with Authentication Bypass Vulnerability
CVE-2026-11883HIGH7.2The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the second-factor authent...
CVE-2026-11823HIGH7.5The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date...
CVE-2026-11794HIGH8.1The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the WordPress...
CVE-2026-11568HIGH7.5The Product Configurator for WooCommerce WordPress plugin before 1.7.3 does not perform any authorisation or post-status...
CVE-2026-10750HIGH8.1The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP tools after ...
CVE-2026-7838HIGH8.8UltraVNC viewer through 1.8.2.2 contains an integer overflow leading to a heap buffer overflow in the RFB protocol failu...
CVE-2026-7831HIGH7.6UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit message handler. In v...
CVE-2026-7830HIGH7.4UltraVNC through 1.8.2.2 uses inadequate cryptography in the MS-Logon II authentication scheme (rfbUltraVNC_MsLogonIIAut...
CVE-2026-7829HIGH7.2UltraVNC repeater through 1.8.2.2 contains a post-authentication out-of-bounds write in the allow/deny rule parser. In r...
CVE-2026-7517HIGH7.2The Custom Payment Gateways for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now