2026 CVE Vulnerabilities

50,985 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-10774MEDIUM6.5Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/blue...
CVE-2026-68583MEDIUM5.4luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field th...
CVE-2026-68582CRITICAL9.3Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-col...
CVE-2026-68581HIGH8.6Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and ...
CVE-2026-68580HIGH7.7FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across AL...
CVE-2026-68579CRITICAL9.6FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_...
CVE-2026-68578HIGH7.7ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine p...
CVE-2026-67357HIGH7.7ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that...
CVE-2026-67356HIGH8.8ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowin...
CVE-2026-12231MEDIUM6.4The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_info...
CVE-2026-18573MEDIUM6.5A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authoriza...
CVE-2026-18572MEDIUM6.5Keycloak provides authorization services that allow administrators to restrict access to resources based on time policie...
CVE-2026-18571HIGH7.2A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled....
CVE-2026-18570MEDIUM5.4A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This componen...
CVE-2026-16540HIGH7.5The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operati...
CVE-2026-16292MEDIUM5.4The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-meta...
CVE-2026-16291MEDIUM4.3The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user befo...
CVE-2026-16285HIGH7.5The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before str...
CVE-2026-16273MEDIUM4.6The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field ...
CVE-2026-16261HIGH7.5The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the req...
CVE-2026-16256CRITICAL9.8The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions av...
CVE-2026-16064MEDIUM5.4The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the o...
CVE-2026-16063MEDIUM5.4The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline cont...
CVE-2026-16062MEDIUM6.6The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-co...
CVE-2026-16042MEDIUM4.3The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowin...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now