2026 CVE Vulnerabilities

64,785 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-90986HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions.
CVE-2026-90887HIGH7.1Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions.
CVE-2026-89418HIGH8.7google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small...
CVE-2026-82760HIGH8.2Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to...
CVE-2026-82685HIGH7.6Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated...
CVE-2026-81632HIGH7.2Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone ab...
CVE-2026-81442HIGH8.1Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerabilit...
CVE-2026-80218HIGH7.6Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for o...
CVE-2026-78295HIGH8.8Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions.
CVE-2026-66631HIGH7.6Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.
CVE-2026-66630HIGH7.6Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.
CVE-2026-66628HIGH7.6Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions.
CVE-2026-66626HIGH7.6Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.
CVE-2026-66625HIGH7.6Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.
CVE-2026-66624HIGH7.6Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.
CVE-2026-66619HIGH7.6Administrator SQL Injection in Newsletters <= 4.18 versions.
CVE-2026-66618HIGH7.6Administrator SQL Injection in WP Maps <= 4.9.9 versions.
CVE-2026-66580HIGH8.5Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.
CVE-2026-66571HIGH7.1Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.
CVE-2026-14850HIGH8.8The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the use...
CVE-2026-92919HIGH8.1admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to ...
CVE-2026-92918HIGH8.8admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events...
CVE-2026-81481HIGH7.5Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Res...
CVE-2026-92925HIGH7.1A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packet...
CVE-2026-92917HIGH7.5Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21, the Twig content sandbox fails to restrict the dump and ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now