2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-16274LOW2.7The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action...
CVE-2026-15231LOW2.7The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to acc...
CVE-2026-18581LOW3.3A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of th...
CVE-2026-15939LOW2.7The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST ...
CVE-2026-67334LOW3.8better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endp...
CVE-2026-67319LOW3.7axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the...
CVE-2026-66401LOW2.1FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fail...
CVE-2026-14823LOW2.2The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of it...
CVE-2026-14214LOW2.7The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be wr...
CVE-2026-14197LOW3.8The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket...
CVE-2026-14195LOW2.7The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning p...
CVE-2026-11882LOW3.7The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes...
CVE-2026-10827LOW3.5The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before usi...
CVE-2026-54787LOW3.1sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle s...
CVE-2026-55825LOW3.1Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an authenticated backend user who can access one job can ...
CVE-2026-57232LOW3.1Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed Reader front-end mod...
CVE-2026-55824LOW2.6Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth cre...
CVE-2026-25552LOW3.7Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rat...
CVE-2026-56569LOW3.3HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal config...
CVE-2026-56567LOW3.3HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of intern...
CVE-2026-65636LOW2.1Improper Neutralization of CRLF Sequences vulnerability in ufirstgroup ymlr (Elixir.Ymlr module) allows attackers to inj...
CVE-2026-18206LOW3.7A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services....
CVE-2026-15381LOW3.7The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a S...
CVE-2026-14927LOW3.7The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership che...
CVE-2026-14862LOW3.7The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downlo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now