2026 CVE Vulnerabilities

50,944 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-9018HIGH8.8The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation ...
CVE-2026-44409HIGH7.5There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control m...
CVE-2026-4834HIGH7.5The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in all versions up to,...
CVE-2026-46597HIGH7.5An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafte...
CVE-2026-39829HIGH7.5The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessive...
CVE-2026-34911HIGH7.7A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in Un...
CVE-2026-8434HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file resc...
CVE-2026-8433HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file resc...
CVE-2026-8432HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star...
CVE-2026-8427HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file remo...
CVE-2026-8416HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addF...
CVE-2026-8415HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/as...
CVE-2026-8414HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/dupl...
CVE-2026-8413HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/...
CVE-2026-8412HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk...
CVE-2026-8411HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/...
CVE-2026-8410HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/...
CVE-2026-8409HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delet...
CVE-2026-8428HIGH8.8Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update')) but...
CVE-2026-8426HIGH8.8Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/prepa...
CVE-2026-8421HIGH8.8Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/singl...
CVE-2026-8417HIGH8.8Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/do_up...
CVE-2026-8350HIGH8.8Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to pr...
CVE-2026-8135HIGH7.2Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the Ex...
CVE-2026-8134HIGH7.2Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTempl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now