2026 CVE Vulnerabilities

43,274 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-55739HIGH8.3Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability ch...
CVE-2026-54418HIGH8.1Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, ...
CVE-2026-54416HIGH7.2Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist i...
CVE-2026-18881HIGH7.5The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filter...
CVE-2026-12000HIGH7.5The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and...
CVE-2026-70375HIGH8.8HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDe...
CVE-2026-70374HIGH8.8HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail genera...
CVE-2026-68073HIGH7.5A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of...
CVE-2026-67592HIGH7.5It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att...
CVE-2026-67590HIGH7.5A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of...
CVE-2026-67552HIGH7.5A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of...
CVE-2026-66274HIGH7.5A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of...
CVE-2026-16736HIGH7.5The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled sett...
CVE-2026-16605HIGH7.2The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to...
CVE-2026-16604HIGH7.5The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before ...
CVE-2026-16603HIGH7.5The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST...
CVE-2026-16602HIGH7.5The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an u...
CVE-2026-16573HIGH7.5The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing un...
CVE-2026-16561HIGH7.5The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX action...
CVE-2026-16055HIGH7.5The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress au...
CVE-2026-16036HIGH7.5The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login ...
CVE-2026-15372HIGH7.5The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported m...
CVE-2026-15230HIGH8.1The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, rely...
CVE-2026-14553HIGH8.1The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied conte...
CVE-2026-8761HIGH8.8The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This i...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now