2026 CVE Vulnerabilities

43,273 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-7529HIGH7.5The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and...
CVE-2026-67623HIGH8.8Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary com...
CVE-2026-17506HIGH7.2The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tr...
CVE-2026-15979HIGH8.1The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Del...
CVE-2026-71294HIGH7.6Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. ...
CVE-2026-71292HIGH7.2Subrion CMS's admin grid sorting helper, _gridGetSorting in includes/classes/ia.base.controller.admin.php, whitelists th...
CVE-2026-71291HIGH8.8Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension registe...
CVE-2026-71288HIGH8.8Koha's guided report builder (reports/guided_reports.pl) reads the CGI parameter and, for each value, a dynamically-name...
CVE-2026-71287HIGH8.8Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex . Because ...
CVE-2026-71285HIGH8.1Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo ...
CVE-2026-71284HIGH7.2Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), takes the fir...
CVE-2026-71281HIGH8.8Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src...
CVE-2026-71280HIGH8.5go-shiori's DownloadBookmark (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Clien...
CVE-2026-71279HIGH8Zigbee2MQTT's ExternalJSExtension.getFilePath (lib/extension/externalJS.ts) joins a parameter received via an MQTT messa...
CVE-2026-71276HIGH7.1Magistrala (formerly Mainflux)'s message-readers API reads a value from the HTTP query string (readers/api/http/transpor...
CVE-2026-71274HIGH8.5OpenBK7231T's CHANNEL_SetLabel (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel co...
CVE-2026-71272HIGH8.5Memos' webhook dispatch function safeDialContext (internal/webhook/webhook.go) resolves the target hostname via net.Defa...
CVE-2026-71271HIGH8.5Memos' webhook URL validation, isReservedIP (internal/webhook/validate.go), checks a candidate IP against a reservedCIDR...
CVE-2026-71270HIGH8.6Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanit...
CVE-2026-71269HIGH7.2Node-RED's local-filesystem library storage module (getLibraryEntry and saveLibraryEntry in packages/node_modules/@node-...
CVE-2026-71266HIGH7.8tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h) reads each line of a .mtl material file into a f...
CVE-2026-71265HIGH7.5Domoticz's MochadTCP::MatchLine handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data ...
CVE-2026-71264HIGH8.2WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson with no settings-PIN check, unlike ...
CVE-2026-71261HIGH7.8dr_libs dr_wav.h (all versions through current master) contains an integer overflow in W64 CUE chunk metadata parsing. I...
CVE-2026-71259HIGH8.6ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now