2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-87119HIGH8.2Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation cre...
CVE-2026-94117HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar –...
CVE-2026-90882HIGH8.7The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-C...
CVE-2026-25265HIGH8.8Privilege escalation due to weak configuration while temporary file handling.
CVE-2026-25264HIGH8.8Privilege escalation due to weak configuration during package extraction process.
CVE-2026-25255HIGH8.8Exposed dangerous function lead to privilege escalation via gRPC server.
CVE-2026-9231HIGH7.5The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inc...
CVE-2026-95508HIGH7.4A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured...
CVE-2026-93928HIGH7.3Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCo...
CVE-2026-68956HIGH7.1Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated remote atta...
CVE-2026-65634HIGH8.2Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated atta...
CVE-2026-93836HIGH7.2The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qty' ...
CVE-2026-93778HIGH7.2The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (import...
CVE-2026-92969HIGH8.1The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Local File Inclusion in a...
CVE-2026-92235HIGH8.1The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, an...
CVE-2026-87082HIGH7.5Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in...
CVE-2026-87081HIGH7.5Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label...
CVE-2026-87079HIGH7.5Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long...
CVE-2026-74766HIGH8.4Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that r...
CVE-2026-6922HIGH7.1The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to Incorrect Authorization in all ve...
CVE-2026-94504HIGH7.2Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy su...
CVE-2026-92438HIGH8.8The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submis...
CVE-2026-91827HIGH7.5The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when a...
CVE-2026-89412HIGH7.2The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross...
CVE-2026-12470HIGH7.2The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unauthorized modificatio...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now