2026 CVE Vulnerabilities

64,785 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-85130HIGH8.8The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for t...
CVE-2026-85128HIGH7.5The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration ...
CVE-2026-87935HIGH8.1The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1...
CVE-2026-25294HIGH7.4Transient DOS while parsing frame during channel usage.
CVE-2026-25290HIGH7.8Memory Corruption when validating large data buffers from external sources using addition to check buffer length.
CVE-2026-25284HIGH7.3Information Disclosure when a pointer is reused after being deallocated.
CVE-2026-25283HIGH8.8Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.
CVE-2026-25282HIGH7.9Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.
CVE-2026-25281HIGH7.4Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.
CVE-2026-25280HIGH7.8Memory corruption when processing escape handling flow with insufficient user buffer sizes.
CVE-2026-25278HIGH7Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copyi...
CVE-2026-25275HIGH7.5Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVE-2026-25261HIGH7.8Memory corruption while processing rear sensor IOCTL calls.
CVE-2026-24081HIGH7.4Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enab...
CVE-2026-24075HIGH7Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper sy...
CVE-2026-24074HIGH7.8Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operat...
CVE-2026-24073HIGH7.8Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
CVE-2026-92838HIGH7.8A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or ...
CVE-2026-81546HIGH7.7The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when pa...
CVE-2026-65388HIGH7.5A remote attacker who controls a container registry may be able to direct a client's token request to a host of the atta...
CVE-2026-61599HIGH8.8djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ...
CVE-2026-61596HIGH7.1djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ...
CVE-2026-92599HIGH7.5joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression de...
CVE-2026-92596HIGH7.5Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows re...
CVE-2026-92594HIGH7.5Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now