2026 CVE Vulnerabilities

51,011 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-13157HIGH7.2The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import ...
CVE-2026-12966MEDIUM5.3The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted ...
CVE-2026-12696MEDIUM5.4The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it in...
CVE-2026-11882LOW3.7The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes...
CVE-2026-10827LOW3.5The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before usi...
CVE-2026-3141CRITICAL9.1The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability chec...
CVE-2026-7623MEDIUM6.4The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Stored Cros...
CVE-2026-15414HIGH8.8The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and incl...
CVE-2026-15403MEDIUM4.9The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection via the 'field' parame...
CVE-2026-15006HIGH7.5The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vuln...
CVE-2026-13362MEDIUM6.4The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_...
CVE-2026-9044HIGH8An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an...
CVE-2026-54909MEDIUM5.3pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed...
CVE-2026-54787LOW3.1sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle s...
CVE-2026-54785MEDIUM6.2gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 unti...
CVE-2026-54768MEDIUM6.9WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPassword...
CVE-2026-53573MEDIUM4.8GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsaf...
CVE-2026-45377MEDIUM6.5Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3...
CVE-2026-45376MEDIUM5.5Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3...
CVE-2026-45330MEDIUM4.9Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3...
CVE-2026-34641HIGH7.8Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co...
CVE-2026-68771CRITICAL9.8ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthentic...
CVE-2026-52371MEDIUM6.5A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticat...
CVE-2026-52232MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150-8T2F Switch 2.2.0D Build...
CVE-2026-52134CRITICAL9.8An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass au...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now