2026 CVE Vulnerabilities

48,529 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-12317HIGH7.5Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
CVE-2026-12314HIGH7.5Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152...
CVE-2026-12312HIGH7.5Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152...
CVE-2026-12310HIGH7.5Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152...
CVE-2026-12305HIGH7.5Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152...
CVE-2026-12292HIGH8.1Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.1...
CVE-2026-12291HIGH8.8Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firef...
CVE-2026-12290HIGH8.1Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115...
CVE-2026-12289HIGH8.8Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140....
CVE-2026-12225HIGH8.7syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vu...
CVE-2026-10829HIGH8.6A stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and earli...
CVE-2026-8442HIGH8.1The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 1...
CVE-2026-8176HIGH7.5The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Esca...
CVE-2026-5416HIGH8.8Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exp...
CVE-2026-54198HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions.
CVE-2026-54191HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions.
CVE-2026-52712HIGH7.6Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions.
CVE-2026-52711HIGH7.5Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.
CVE-2026-39581HIGH8.5Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.
CVE-2026-39490HIGH7.5Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.
CVE-2026-39437HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 versions.
CVE-2026-10825HIGH7.1A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based ...
CVE-2026-8444HIGH8.8The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpf...
CVE-2026-46331HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page ca...
CVE-2026-8443HIGH8.8The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameter...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now