2026 CVE Vulnerabilities

50,995 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-9335MEDIUM6.5A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improp...
CVE-2026-8457CRITICAL9.8The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and inc...
CVE-2026-18352HIGH7.5The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, ...
CVE-2026-13339HIGH7.5The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1...
CVE-2026-17002Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-18556HIGH7.4Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass....
CVE-2026-55735HIGH7.5Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a vi...
CVE-2026-55734HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) a...
CVE-2026-55733HIGH7.5Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c...
CVE-2026-54894HIGH7.5Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c...
CVE-2026-67355HIGH8.2guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain...
CVE-2026-67354HIGH8.2guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the...
CVE-2026-67353MEDIUM6.9guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimit...
CVE-2026-67352HIGH7.6luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows ...
CVE-2026-67344HIGH8.5ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYP...
CVE-2026-67343HIGH8.8ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing a...
CVE-2026-67342CRITICAL9.8ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, P...
CVE-2026-67341CRITICAL9.8ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with...
CVE-2026-67340HIGH7.2ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) b...
CVE-2026-67339MEDIUM6.9guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cUR...
CVE-2026-67338MEDIUM6.1JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to vali...
CVE-2026-67337HIGH7.1better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is e...
CVE-2026-67336CRITICAL9.4better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that adve...
CVE-2026-67335MEDIUM6better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-...
CVE-2026-67334MEDIUM5.1better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endp...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now