2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-93563HIGH7.5A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-midd...
CVE-2026-81627HIGH8.2A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias rem...
CVE-2026-87915HIGH7.2The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress ...
CVE-2026-87743HIGH7.5A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normal...
CVE-2026-18405HIGH7.2The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vul...
CVE-2026-15579HIGH8.8An out-of-bounds write vulnerability exists in some of the Ethernet switches because of improper validation of the usern...
CVE-2026-85410HIGH8.1The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template...
CVE-2026-83561HIGH7.2The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comm...
CVE-2026-6205HIGH8.1An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-...
CVE-2026-40539HIGH7.1An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-1...
CVE-2026-40530HIGH8An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manage...
CVE-2026-13673HIGH8.8An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM)...
CVE-2026-93494HIGH7.5A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending ...
CVE-2026-89059HIGH7.5A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing ...
CVE-2026-89058HIGH7.4A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Ori...
CVE-2026-85705HIGH7.5The Location Manager plugin for WordPress is vulnerable to generic SQL Injection via 'latitude' and 'longitude' REST API...
CVE-2026-75157HIGH7.5Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `E...
CVE-2026-67103HIGH7.6HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to ...
CVE-2026-67102HIGH8.1HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a lo...
CVE-2026-18442HIGH7.5The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic SQL Injecti...
CVE-2026-15275HIGH7.5The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_searc...
CVE-2026-14323HIGH7.5The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in...
CVE-2026-12954HIGH8.8The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including...
CVE-2026-12384HIGH8.8Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse. ...
CVE-2026-92619HIGH7.2The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now