2026 CVE Vulnerabilities

50,985 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-4031HIGH7.5The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and ...
CVE-2026-4030HIGH8.1The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in...
CVE-2026-4029HIGH7.5The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up ...
CVE-2026-8468HIGH8.2Allocation of Resources Without Limits or Throttling vulnerability in plug_project plug allows denial of service via unb...
CVE-2026-6514HIGH7.5The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2...
CVE-2026-6506HIGH8.8The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.1....
CVE-2026-5395HIGH8.2The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne...
CVE-2026-3892HIGH8.1The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion i...
CVE-2026-3718HIGH7.2The ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'MWP-Key-Name' HTTP reques...
CVE-2026-5396HIGH8.2The Fluent Forms plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions ...
CVE-2026-1659HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.9.7, 18.10 before 18.10.6, and ...
CVE-2026-1322HIGH8.1GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 before 18.9.7, 18.10 before 18.10.6, and...
CVE-2026-1184HIGH7.5GitLab has remediated an issue in GitLab EE affecting all versions from 11.9 before 18.9.7, 18.10 before 18.10.6, and 18...
CVE-2026-46446HIGH7.1SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This i...
CVE-2026-46445HIGH7.1SOGo before 5.12.7, when PostgreSQL is used, allows SQL injection.
CVE-2026-46419HIGH7.5Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value i...
CVE-2026-32991HIGH7.1Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner ac...
CVE-2026-29206HIGH8.1Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the roo...
CVE-2026-44478HIGH7.5hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the una...
CVE-2026-44471HIGH7.8gitoxide is an implementation of git written in Rust. Prior to 0.21.1, a malicious tree can be constructed that will, wh...
CVE-2026-44447HIGH7.5ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to ...
CVE-2026-44446HIGH7.5ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were ...
CVE-2026-44439HIGH7.5PlaywrightCapture is a simple replacement for splash using playwright. Prior to 1.39.6, PlaywrightCapture did not suffic...
CVE-2026-44369HIGH8.5CVAT is an open source interactive video and image annotation tool for computer vision. From 2.5.0 to 2.63.0, an attacke...
CVE-2026-42463HIGH8.1SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now