2026 CVE Vulnerabilities

49,638 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-28005CRITICAL9.8Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
CVE-2026-25403MEDIUM6.5Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
CVE-2026-19045MEDIUM5.3A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog...
CVE-2026-19044MEDIUM5.3A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of...
CVE-2026-15246MEDIUM4.3The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, no...
CVE-2026-64993CRITICAL9.1Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remo...
CVE-2026-5134CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Info...
CVE-2026-19041MEDIUM6.3A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the function this.packageSe...
CVE-2026-19040MEDIUM6.3A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown function of the file src/...
CVE-2026-18501MEDIUM6.4The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre...
CVE-2026-16731HIGH8.3OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authe...
CVE-2026-16316MEDIUM4.3OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame...
CVE-2026-16315HIGH8.7OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authe...
CVE-2026-12605CRITICAL9.6In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfrestt...
CVE-2026-70556MEDIUM5.1Hubzilla versions prior to 11.4 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint h...
CVE-2026-66733HIGH8.7Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enque...
CVE-2026-66732HIGH8.3Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager whe...
CVE-2026-65551HIGH7.5Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Securit...
CVE-2026-19039MEDIUM5.3A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted ...
CVE-2026-19038MEDIUM6.3A security vulnerability has been detected in MonomythDevelopment la-forge-mcp 1.0.0. This issue affects the function sc...
CVE-2026-19037MEDIUM4.3A weakness has been identified in WonderTrader up to 0.9.9. This vulnerability affects the function MatchEngine::update_...
CVE-2026-19036HIGH7.3A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/pp...
CVE-2026-15599LOW3.3Unverified ownership vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-domain-joiner allow...
CVE-2026-0673MEDIUM5.3The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to...
CVE-2026-8166MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Indu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now