2026 CVE Vulnerabilities

50,909 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-45837HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Fix use-after-free in arena_vm_close on fork ...
CVE-2026-42762HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBookin...
CVE-2026-42760HIGH7.5Authentication Bypass Using an Alternate Path or Channel vulnerability in revmakx Backup and Staging by WP Time Capsule ...
CVE-2026-42759HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timo Affiliate Sup...
CVE-2026-42754HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phbernard Favicon ...
CVE-2026-42753HIGH7.3Missing Authorization vulnerability in WC Lovers WCFM Membership wc-multivendor-membership allows Exploiting Incorrectly...
CVE-2026-42749HIGH7.1Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeisle Disable Comments for Any Post Types ...
CVE-2026-42746HIGH7.3Insertion of Sensitive Information Into Sent Data vulnerability in ZAYTECH Smart Online Order for Clover clover-online-o...
CVE-2026-42745HIGH7.3Authentication Bypass Using an Alternate Path or Channel vulnerability in ZAYTECH Smart Online Order for Clover clover-o...
CVE-2026-42739HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IniLerm Advanced I...
CVE-2026-42738HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZAYTECH Smart Onli...
CVE-2026-42737HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in e4jvikwp VikBooking Hote...
CVE-2026-42736HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in wordplus BP Better Messages bp-better-messages allows ...
CVE-2026-42735HIGH8.2Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-managem...
CVE-2026-42734HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Ma...
CVE-2026-42733HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 WPCS cu...
CVE-2026-42730HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStu...
CVE-2026-42729HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive Prop...
CVE-2026-42728HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Cont...
CVE-2026-40852HIGH7.2A highly authenticated attacker can alter the config generator injecting a payload into future created configurations. T...
CVE-2026-40851HIGH8.4A local attacker can perform a confusion attack on the cfgparser via a specially crafted file on an USB stick leading to...
CVE-2026-40850HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountData func...
CVE-2026-40849HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the user_alarmprofile vi...
CVE-2026-40848HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the tag view due to impr...
CVE-2026-40847HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system_tag view due ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now