2026 CVE Vulnerabilities

53,146 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-65445MEDIUM6.5Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.
CVE-2026-65443HIGH7.1Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.
CVE-2026-65442HIGH7.2Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
CVE-2026-65441HIGH7.1Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.
CVE-2026-65440HIGH7.1Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.
CVE-2026-65439HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.
CVE-2026-65438HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.
CVE-2026-65437HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.
CVE-2026-61957HIGH7.1Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.
CVE-2026-61953HIGH7.2Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
CVE-2026-51565MEDIUM6.1Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attacker...
CVE-2026-59240MEDIUM6.9The vulnerability involves an Insecure Direct Object Reference (IDOR) in the `DeleteNotificationController::delete()` me...
CVE-2026-55685HIGH7.5React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauth...
CVE-2026-53669MEDIUM6.1React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backsl...
CVE-2026-53668MEDIUM6.9React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow ...
CVE-2026-53667MEDIUM6.1React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validatio...
CVE-2026-53666MEDIUM6.1React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allo...
CVE-2026-51564MEDIUM4.9An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect users to arbitrary external...
CVE-2026-51078HIGH7.5An issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the str parameter of the fil...
CVE-2026-51077HIGH7.5SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the sqlqu...
CVE-2026-66825MEDIUM6.9Pivotick contains a cross-site scripting vulnerability in the sidebar property-list component. Values associated with li...
CVE-2026-66824CRITICAL9.2A stored cross-site scripting vulnerability existed in the capture tree visualization page. The application embedded the...
CVE-2026-64783HIGH8.8A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and i...
CVE-2026-64776MEDIUM5.5The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, m...
CVE-2026-64775CRITICAL9.8A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now