2026 CVE Vulnerabilities

51,426 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-7647HIGH8.1The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3...
CVE-2026-7049HIGH7.2The PixelYourSite Pro – Your smart PIXEL (TAG) Manager plugin for WordPress is vulnerable to Server-Side Request Forgery...
CVE-2026-5113HIGH7.2The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in v...
CVE-2026-5112HIGH7.2The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to an...
CVE-2026-5111HIGH7.2The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10...
CVE-2026-5110HIGH7.2The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to an...
CVE-2026-5109HIGH7.2The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10...
CVE-2026-7641HIGH8.8The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up ...
CVE-2026-6963HIGH8.8The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the w...
CVE-2026-43824HIGH7.7In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.
CVE-2026-7598HIGH7.3A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_passwo...
CVE-2026-7594HIGH7.3A vulnerability was detected in Flux159 mcp-game-asset-gen 0.1.0. Affected is the function image_to_3d_async of the file...
CVE-2026-7593HIGH7.3A security vulnerability has been detected in Sunwood-ai-labs command-executor-mcp-server up to 0.1.0. This impacts the ...
CVE-2026-42786HIGH8.7Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denia...
CVE-2026-39804HIGH8.2Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denia...
CVE-2026-7592HIGH7.3A weakness has been identified in itsourcecode Courier Management System 1.0. This affects an unknown function of the fi...
CVE-2026-7590HIGH7.3A vulnerability was identified in eyal-gor p_69_branch_monkey_mcp up to 69bc71874ce40050ef45fde5a435855f18af3373. The af...
CVE-2026-30363HIGH8.4flipperzero-firmware commit ad2a80 was discovered to contain a stack overflow in the "Main" function.
CVE-2026-37457HIGH7.5An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of F...
CVE-2026-42485HIGH7.5AGL agl-service-can-low-level contains a stack buffer overflow in the uds-c library. The send_diagnostic_request functio...
CVE-2026-42469HIGH8.6Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_canswitch.cpp the parser...
CVE-2026-42468HIGH8.8Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_pcap.cpp , the parser's ...
CVE-2026-42467HIGH7.5An issue was discovered in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in SAE_J1939...
CVE-2026-37538HIGH7.5Buffer overflow vulnerability in socketcand 0.4.2 in file socketcand.c in function main allows attackers to cause a deni...
CVE-2026-37537HIGH8.1collin80/Open-SAE-J1939 thru commit 744024d4306bc387857dfce439558336806acb06 (2023-03-08) contains an integer underflow ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now