2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-89413HIGH8.1The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1....
CVE-2026-93485HIGH7.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPre...
CVE-2026-90978HIGH7.1The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonc...
CVE-2026-88825HIGH8.8The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowin...
CVE-2026-87775HIGH8.6The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to ...
CVE-2026-87774HIGH8.6The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to ...
CVE-2026-87771HIGH8.6The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them...
CVE-2026-87770HIGH8.6The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using ...
CVE-2026-87767HIGH8.6The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter bef...
CVE-2026-85127HIGH8.8The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthentic...
CVE-2026-85122HIGH8.8The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stor...
CVE-2026-81810HIGH7.2The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of...
CVE-2026-18912HIGH7.7ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allo...
CVE-2026-18911HIGH7.5ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolle...
CVE-2026-17086HIGH8.8The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object I...
CVE-2026-93468HIGH7.5The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit R...
CVE-2026-93371HIGH8.3A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function Ne...
CVE-2026-93456HIGH8.2django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing ...
CVE-2026-93331HIGH7.3A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file ...
CVE-2026-79954HIGH8.7NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiv...
CVE-2026-93453HIGH8.3SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing u...
CVE-2026-93452HIGH7.5snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that wr...
CVE-2026-93450HIGH7.5go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serializatio...
CVE-2026-85887HIGH7.7Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose informat...
CVE-2026-93436HIGH7.5vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode di...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now