2026 CVE Vulnerabilities

48,530 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-6933HIGH8.8The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in version...
CVE-2026-7273HIGH8.8A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABT...
CVE-2026-1767HIGH8.1A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` compo...
CVE-2026-12161HIGH8.8Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or mo...
CVE-2026-9262HIGH7.5Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier
CVE-2026-53430HIGH8.7Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-grpc grpc (GRPC.Compressor.Gzip...
CVE-2026-48854HIGH8.7Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers ...
CVE-2026-48723HIGH7.8The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on BrowserStack. Versions pri...
CVE-2026-48599HIGH7.6Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to acc...
CVE-2026-5064HIGH8.5Potential security vulnerabilities have been identified in the HP One Agent for certain HP PC products, which might all...
CVE-2026-48017HIGH8.8DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate...
CVE-2026-52702HIGH7.1Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions.
CVE-2026-52700HIGH8.5Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.
CVE-2026-52699HIGH7.5Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions.
CVE-2026-52697HIGH8.5Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.
CVE-2026-52695HIGH7.5Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.
CVE-2026-52694HIGH7.5Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.
CVE-2026-52692HIGH7.5Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions.
CVE-2026-49780HIGH8.8Customer Privilege Escalation in Dokan <= 5.0.2 versions.
CVE-2026-49112HIGH7.5Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.
CVE-2026-49110HIGH7.5Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions.
CVE-2026-49083HIGH7.5Contributor Privilege Escalation in LatePoint <= 5.5.1 versions.
CVE-2026-49082HIGH7.4Subscriber Sensitive Data Exposure in Chatway Live Chat &#8211; AI Chatbot, Customer Support, FAQ &amp; Helpdesk Custome...
CVE-2026-49078HIGH7.5Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions.
CVE-2026-49070HIGH7.5Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now