2026 CVE Vulnerabilities

43,273 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-18967HIGH8.1A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured a...
CVE-2026-18510HIGH7.2The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross...
CVE-2026-18050HIGH7.5The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves tem...
CVE-2026-16734HIGH7.5The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe p...
CVE-2026-16268HIGH8.2The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetchi...
CVE-2026-14829HIGH8.2The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not pr...
CVE-2026-13154HIGH7.5The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is pub...
CVE-2026-13153HIGH7.5The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes ...
CVE-2026-19000HIGH7.3A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/...
CVE-2026-15459HIGH8.1The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,...
CVE-2026-18325HIGH7.2The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cro...
CVE-2026-16636HIGH7.2The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for Wo...
CVE-2026-15991HIGH8.8The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation ...
CVE-2026-18991HIGH7.3A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file c...
CVE-2026-18990HIGH7.3A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts o...
CVE-2026-18973HIGH7.3A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitiz...
CVE-2026-67872HIGH7.5An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event monitored-item queu...
CVE-2026-67871HIGH7.5Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddN...
CVE-2026-67869HIGH7.5Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_...
CVE-2026-18970HIGH7.3A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected elemen...
CVE-2026-18969HIGH7.3A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is ...
CVE-2026-67867HIGH7.5Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Alar...
CVE-2026-67866HIGH7.5Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Lock...
CVE-2026-67863HIGH7.5In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when ...
CVE-2026-19024HIGH8.2NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.3.0 allows attackers to cause a denial of service via a d...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now