2026 CVE Vulnerabilities

48,931 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-19041MEDIUM6.3A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the function this.packageSe...
CVE-2026-19040MEDIUM6.3A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown function of the file src/...
CVE-2026-18501MEDIUM6.4The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre...
CVE-2026-16731HIGH8.3OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authe...
CVE-2026-16316MEDIUM4.3OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame...
CVE-2026-16315HIGH8.7OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authe...
CVE-2026-12605CRITICAL9.6In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfrestt...
CVE-2026-70556MEDIUM5.1Hubzilla versions prior to 11.4 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint h...
CVE-2026-66733HIGH8.7Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enque...
CVE-2026-66732HIGH8.3Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager whe...
CVE-2026-65551HIGH7.5Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Securit...
CVE-2026-19039MEDIUM5.3A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted ...
CVE-2026-19038MEDIUM6.3A security vulnerability has been detected in MonomythDevelopment la-forge-mcp 1.0.0. This issue affects the function sc...
CVE-2026-19037MEDIUM4.3A weakness has been identified in WonderTrader up to 0.9.9. This vulnerability affects the function MatchEngine::update_...
CVE-2026-19036HIGH7.3A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/pp...
CVE-2026-15599LOW3.3Unverified ownership vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-domain-joiner allow...
CVE-2026-0673MEDIUM5.3The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to...
CVE-2026-8166MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Indu...
CVE-2026-68481HIGH7.5In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospec...
CVE-2026-68079CRITICAL9.8In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of ...
CVE-2026-65583CRITICAL9.1Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim che...
CVE-2026-63687CRITICAL9.1Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map witho...
CVE-2026-61466CRITICAL9.1In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` val...
CVE-2026-5391MEDIUM6.4The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute ...
CVE-2026-5158MEDIUM6.4The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored C...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now