2026 CVE Vulnerabilities

64,772 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-93959HIGH7.3A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown ...
CVE-2026-94056HIGH7.5Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uni...
CVE-2026-93993HIGH8.8Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes...
CVE-2026-93992HIGH8.1Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write...
CVE-2026-93991HIGH7.7Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that ...
CVE-2026-93990HIGH7.5Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-1...
CVE-2026-82560HIGH7.5Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting d...
CVE-2026-1255HIGH7.5The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including...
CVE-2026-85658HIGH8.1The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres...
CVE-2026-4327HIGH8.8The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1...
CVE-2026-15664HIGH7.2The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-...
CVE-2026-92404HIGH7.5The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowi...
CVE-2026-88926HIGH8.6The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of it...
CVE-2026-88824HIGH8.8The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthe...
CVE-2026-86814HIGH8.1The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an e...
CVE-2026-85680HIGH8.8The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names bef...
CVE-2026-85574HIGH8The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the conf...
CVE-2026-76790HIGH7.1The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a ...
CVE-2026-76554HIGH7.2The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to...
CVE-2026-92807HIGH8.8The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions u...
CVE-2026-87909HIGH7.5The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_m...
CVE-2026-13354HIGH7.2The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Cont...
CVE-2026-93923HIGH8.8SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing st...
CVE-2026-93922HIGH8.8SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing store...
CVE-2026-88097HIGH7.8Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now