2026 CVE Vulnerabilities

52,116 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-17166MEDIUM4.3The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress...
CVE-2026-17162MEDIUM6.4The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2026-17161MEDIUM6.4The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2026-15735MEDIUM6.4The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cf7anyapi_form_field'...
CVE-2026-12939MEDIUM6.4The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the p...
CVE-2026-12938MEDIUM6.4The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the...
CVE-2026-12144HIGH8.8The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and incl...
CVE-2026-56822HIGH7.4Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ...
CVE-2026-56821HIGH7.4Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ...
CVE-2026-66064MEDIUM5.3goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler...
CVE-2026-66063MEDIUM6.5goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown....
CVE-2026-64863CRITICAL9.1goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server....
CVE-2026-62325CRITICAL9.1goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver...
CVE-2026-59921MEDIUM6.5Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ...
CVE-2026-54719HIGH7.5goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown....
CVE-2026-54659MEDIUM6.9Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18...
CVE-2026-54658CRITICAL9.8Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.5.1, escapeValue() in packages/clickhouse/src/core/u...
CVE-2026-54650HIGH8.6openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/publ...
CVE-2026-54638HIGH7.5gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted...
CVE-2026-47219HIGH7.5find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and w...
CVE-2026-55415HIGH7.5datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch...
CVE-2026-55403LOW3.7datamodel-code-generator generates Python data models from schema definitions. Prior to 0.63.0, src/datamodel_code_gener...
CVE-2026-55391HIGH7.5datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch...
CVE-2026-55390HIGH7.5datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema pars...
CVE-2026-55389HIGH7.5datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now