2026 CVE Vulnerabilities

53,017 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33385MEDIUM5.1A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a hig...
CVE-2026-14354HIGH8.7CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorize...
CVE-2026-12927HIGH8.4CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execut...
CVE-2026-0667CRITICAL9.3CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, d...
CVE-2026-14270HIGH8.8The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerabl...
CVE-2026-8791MEDIUM6.4The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` ...
CVE-2026-7436MEDIUM6.4The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text...
CVE-2026-6089MEDIUM4.9The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the 'sticky_s_media' parameter in impor...
CVE-2026-65883CRITICAL9.8Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A fo...
CVE-2026-5060MEDIUM6.5The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure D...
CVE-2026-56390MEDIUM6.3GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifyi...
CVE-2026-56389HIGH8.6GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of gram...
CVE-2026-50642MEDIUM4.8diff‑so‑fancy does not properly sanitize non‑SGR terminal control sequences before outputting diff data. The application...
CVE-2026-4604MEDIUM5.3The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...
CVE-2026-18220HIGH7.8An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. T...
CVE-2026-16655HIGH7.2The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne...
CVE-2026-16597HIGH7.2The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scr...
CVE-2026-14900CRITICAL9.8The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i...
CVE-2026-14488CRITICAL9.1The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the...
CVE-2026-12895HIGH7.1SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries...
CVE-2026-65100MEDIUM6.3Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so...
CVE-2026-59243CRITICAL9.8The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacke...
CVE-2026-58189HIGH8.2Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. T...
CVE-2026-58188HIGH8.4Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apach...
CVE-2026-58187HIGH7.5The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of serv...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now