2026 CVE Vulnerabilities

53,362 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-16910MEDIUM5.5A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers acc...
CVE-2026-16519HIGH7.3A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads on...
CVE-2026-15755MEDIUM6.4The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Short...
CVE-2026-15665MEDIUM6.4The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2026-15653MEDIUM6.4The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2026-15648MEDIUM6.4The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attri...
CVE-2026-15464MEDIUM6.4The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Att...
CVE-2026-15334MEDIUM6.4The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress...
CVE-2026-15333MEDIUM6.4The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress...
CVE-2026-12654MEDIUM5.3The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up...
CVE-2026-14603HIGH7.5The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint...
CVE-2026-14172HIGH7.8Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without ...
CVE-2026-12981HIGH7.5The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user pas...
CVE-2026-12877CRITICAL9.1The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user s...
CVE-2026-12690LOW3.8The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, ...
CVE-2026-12689MEDIUM5.4The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its pr...
CVE-2026-12688MEDIUM6.5The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group mem...
CVE-2026-12497HIGH7.5The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl...
CVE-2026-16870HIGH8.8Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execut...
CVE-2026-66141HIGH7.8Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
CVE-2026-66140HIGH7.8Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privilege...
CVE-2026-66139MEDIUM4.8OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.
CVE-2026-66138HIGH7.2In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code ...
CVE-2026-54422MEDIUM5.5In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, m...
CVE-2026-6454MEDIUM6.4The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and inclu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now