2026 CVE Vulnerabilities

43,277 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-59641HIGH8.7In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This iss...
CVE-2026-59640HIGH8.7In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue ...
CVE-2026-59639HIGH8.7In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue al...
CVE-2026-12185HIGH7.1In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This i...
CVE-2026-3245HIGH7.7A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.
CVE-2026-18577HIGH8.1An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions throu...
CVE-2026-10848HIGH8.6The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j...
CVE-2026-9856HIGH7.1A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes vi...
CVE-2026-68581HIGH8.6Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and ...
CVE-2026-68580HIGH7.7FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across AL...
CVE-2026-68578HIGH7.7ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine p...
CVE-2026-67357HIGH7.7ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that...
CVE-2026-67356HIGH8.8ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowin...
CVE-2026-18571HIGH7.2A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled....
CVE-2026-16540HIGH7.5The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operati...
CVE-2026-16285HIGH7.5The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before str...
CVE-2026-16261HIGH7.5The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the req...
CVE-2026-15241HIGH7.5The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one o...
CVE-2026-15236HIGH7.5The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party...
CVE-2026-15206HIGH7.5The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that w...
CVE-2026-15151HIGH7.5The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its ...
CVE-2026-14920HIGH8.2## Summary
CVE-2026-12586HIGH8.1The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset...
CVE-2026-18352HIGH7.5The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, ...
CVE-2026-13339HIGH7.5The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now