2026 CVE Vulnerabilities

50,937 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-61484CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apac...
CVE-2026-61483HIGH7.5** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: al...
CVE-2026-5651MEDIUM4.9The Askeet plugin for WordPress is vulnerable to SQL Injection via the 'sql_query' parameter in multiple AJAX actions (a...
CVE-2026-5581CRITICAL9.1The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all ...
CVE-2026-5116MEDIUM4.4The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all ver...
CVE-2026-5108MEDIUM4.4The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `superpwa_setti...
CVE-2026-59675HIGH7.5When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a siz...
CVE-2026-55998MEDIUM5.3The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid ...
CVE-2026-55997HIGH8.8Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These token...
CVE-2026-55996MEDIUM4.3A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent com...
CVE-2026-55747MEDIUM6.8The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin os.path.join(workdir...
CVE-2026-55739HIGH8.3Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability ch...
CVE-2026-54418HIGH8.1Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, ...
CVE-2026-54416HIGH7.2Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist i...
CVE-2026-4431CRITICAL9.1The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2026-18881HIGH7.5The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filter...
CVE-2026-17532MEDIUM6.1The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'seraph_accel_p...
CVE-2026-17505MEDIUM6.1The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v...
CVE-2026-15281MEDIUM6.5The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the w...
CVE-2026-12000HIGH7.5The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and...
CVE-2026-11977MEDIUM6.5The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to ...
CVE-2026-11969MEDIUM4.9The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Paramete...
CVE-2026-11920MEDIUM4.9The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL ...
CVE-2026-11454MEDIUM6.5The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object...
CVE-2026-71201MEDIUM5In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assign...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now