2026 CVE Vulnerabilities

43,277 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-67301HIGH8.7FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC an...
CVE-2026-67300HIGH8.7FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAI...
CVE-2026-67299HIGH8.7FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER...
CVE-2026-67298HIGH8.7FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_...
CVE-2026-67297HIGH8.7FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses...
CVE-2026-67296HIGH8.7FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to valid...
CVE-2026-67291HIGH8.7FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments...
CVE-2026-67290HIGH8.7FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG...
CVE-2026-67288HIGH8.7FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept ...
CVE-2026-18536HIGH7.5Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource:...
CVE-2026-16635HIGH8.8The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0...
CVE-2026-16144HIGH8.1The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all...
CVE-2026-15450HIGH8.1The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path trav...
CVE-2026-15052HIGH7.2The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cr...
CVE-2026-15988HIGH8.8The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request F...
CVE-2026-15368HIGH8.1The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after use...
CVE-2026-15244HIGH7.2The HUSKY WordPress plugin before 1.4.1 does not sanitize a stored setting value against directory traversal before con...
CVE-2026-14839HIGH7.5The Mapster WP Maps WordPress plugin before 1.24.0 does not perform any authorization or post-status check on a public R...
CVE-2026-14836HIGH8.1The Login & Register Forms WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset...
CVE-2026-14596HIGH8.8The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used as the...
CVE-2026-14309HIGH8.1The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been ...
CVE-2026-13725HIGH7.1The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user ...
CVE-2026-13158HIGH7.2The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content impo...
CVE-2026-13157HIGH7.2The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import ...
CVE-2026-15414HIGH8.8The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and incl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now