2026 CVE Vulnerabilities

52,215 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-17162MEDIUM6.4The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2026-17161MEDIUM6.4The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2026-15735MEDIUM6.4The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cf7anyapi_form_field'...
CVE-2026-12939MEDIUM6.4The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the p...
CVE-2026-12938MEDIUM6.4The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the...
CVE-2026-12144HIGH8.8The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and incl...
CVE-2026-56822HIGH7.4Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ...
CVE-2026-56821HIGH7.4Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ...
CVE-2026-66064MEDIUM5.3goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler...
CVE-2026-66063MEDIUM6.5goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown....
CVE-2026-64863CRITICAL9.1goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server....
CVE-2026-62325CRITICAL9.1goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver...
CVE-2026-59921MEDIUM6.5Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ...
CVE-2026-54719HIGH7.5goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown....
CVE-2026-54659MEDIUM6.9Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18...
CVE-2026-54658CRITICAL9.8Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.5.1, escapeValue() in packages/clickhouse/src/core/u...
CVE-2026-54650HIGH8.6openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/publ...
CVE-2026-54638HIGH7.5gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted...
CVE-2026-47219HIGH7.5find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and w...
CVE-2026-55415HIGH7.5datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch...
CVE-2026-55403LOW3.7datamodel-code-generator generates Python data models from schema definitions. Prior to 0.63.0, src/datamodel_code_gener...
CVE-2026-55391HIGH7.5datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch...
CVE-2026-55390HIGH7.5datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema pars...
CVE-2026-55389HIGH7.5datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch...
CVE-2026-54691HIGH8.2datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_co...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now