2026 CVE Vulnerabilities

49,638 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-14240MEDIUM5.3The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its pub...
CVE-2026-14204MEDIUM6.5The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, all...
CVE-2026-13703MEDIUM5.4The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated...
CVE-2026-13154HIGH7.5The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is pub...
CVE-2026-13153HIGH7.5The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes ...
CVE-2026-12713CRITICAL9.1The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using i...
CVE-2026-11588MEDIUM6.1The EONSR AEO Agent WordPress plugin through 3.7.9 does not perform any authorisation check on one of its REST API route...
CVE-2026-19000HIGH7.3A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/...
CVE-2026-18998MEDIUM6.3A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of ...
CVE-2026-18997MEDIUM6.3A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBg...
CVE-2026-15459HIGH8.1The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,...
CVE-2026-18996MEDIUM6.3A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.12. This vulnerability affects the function P...
CVE-2026-18995MEDIUM4.3A flaw has been found in netease-youdao LobsterAI 2026.6.10. This affects the function parseMediaTokensFromText of the f...
CVE-2026-18993MEDIUM6.3A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functiona...
CVE-2026-18992MEDIUM6.3A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of ...
CVE-2026-18909MEDIUM5.6A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and...
CVE-2026-18325HIGH7.2The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cro...
CVE-2026-16636HIGH7.2The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for Wo...
CVE-2026-15991HIGH8.8The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation ...
CVE-2026-18991HIGH7.3A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file c...
CVE-2026-18990HIGH7.3A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts o...
CVE-2026-18980MEDIUM6.3A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the fi...
CVE-2026-18976MEDIUM6.3A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions...
CVE-2026-18974MEDIUM5.5A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the...
CVE-2026-18973HIGH7.3A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitiz...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now