2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-62431HIGH7.5The logic to handle periodic Viridian STIMERs performs a division with an unchecked user-controlled divisor value, that ...
CVE-2026-62430HIGH7.5Accesses to the CMOS memory contents are done using an indirect IO port pair. Therefore Xen needs to cache the guest ch...
CVE-2026-62429MEDIUM6.5Accessing the vNUMA configuration data of a guest is still possible when domain destruction has already started. The cl...
CVE-2026-62428HIGH7.8When grant-copy operations are processed, the respective grant may or may not already be in use by another operation (a ...
CVE-2026-62427HIGH8.8[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-62426HIGH8.8[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-62425MEDIUM5.5[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-62424MEDIUM5.5[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-62423MEDIUM5.5[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-49332HIGH8.5A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X...
CVE-2026-42495MEDIUM5.5[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-42494MEDIUM6.1[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-42493HIGH7.5Addressing certain issues, in particular related to operations which may take excessively long and therefore would need ...
CVE-2026-42492HIGH7.5Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. To m...
CVE-2026-41874MEDIUM6.8Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with acces...
CVE-2026-18047MEDIUM6.5A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching fo...
CVE-2026-18038MEDIUM4.3A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function ExecTool.E...
CVE-2026-15393MEDIUM6.4The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress...
CVE-2026-15016MEDIUM6.4The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerab...
CVE-2026-4648MEDIUM6.8Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from CasfID Servicios Tec...
CVE-2026-21047HIGH8.3Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitra...
CVE-2026-16774MEDIUM5.3The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the ...
CVE-2026-16773MEDIUM5.3The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive In...
CVE-2026-15444MEDIUM4.9The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the...
CVE-2026-15411MEDIUM5.3The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now