2026 CVE Vulnerabilities

48,281 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-9710HIGH7.7The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview request handl...
CVE-2026-9709HIGH7.7The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing...
CVE-2026-9643HIGH7.2The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI se...
CVE-2026-9179HIGH7.5The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/...
CVE-2026-9178HIGH7.5The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, ...
CVE-2026-8705HIGH7.5The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter of th...
CVE-2026-4297HIGH8.8The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and...
CVE-2026-13006HIGH7ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.3...
CVE-2026-12100HIGH7.2The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ...
CVE-2026-12095HIGH7.2The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ...
CVE-2026-10749HIGH7.2The Post Duplicator WordPress plugin before 3.0.15 does not safely handle custom meta-data during post duplication, stor...
CVE-2026-10735HIGH7.5Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, P...
CVE-2026-10092HIGH7.2The Cincopa video and media plug-in plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cincopa Shortc...
CVE-2026-10091HIGH7.2The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' sh...
CVE-2026-3652HIGH7.2The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf_save...
CVE-2026-12681HIGH8.9Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation. parseEfiSig...
CVE-2026-54639HIGH8.8Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulnerability starting in...
CVE-2026-7574HIGH8.7Anthropic Claude Desktop Cowork VM image handling (confirmed across v1.1348.0 through v1.2278.0, including v1.1348.0, v1...
CVE-2026-5818HIGH7.2Incorrect check of function return value in Caliptra Core Runtime Firmware (ActivateFirmwareCmd::activate_fw modules) al...
CVE-2026-56785HIGH8.4FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email f...
CVE-2026-11972HIGH8.2When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly h...
CVE-2026-54513HIGH8.1jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From...
CVE-2026-54512HIGH8.1jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From...
CVE-2026-50193HIGH7.5jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From...
CVE-2026-47387HIGH8.4NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the shared form-view submit handler (pack...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now