2026 CVE Vulnerabilities

53,451 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-16287HIGH7.8Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILG...
CVE-2026-9729MEDIUM6.4The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_noti...
CVE-2026-9713HIGH7.5The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table'...
CVE-2026-9635MEDIUM6.4The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parame...
CVE-2026-59678HIGH7.1An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary fi...
CVE-2026-59677MEDIUM6.8A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined ...
CVE-2026-12421HIGH7.2The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all version...
CVE-2026-9577MEDIUM4.8The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before ref...
CVE-2026-9066MEDIUM6.1The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asse...
CVE-2026-59676MEDIUM5.8A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user ...
CVE-2026-14291HIGH7.5The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its ...
CVE-2026-12082HIGH7.5The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes...
CVE-2026-7534HIGH7.2The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST AP...
CVE-2026-7232HIGH7.2The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in ...
CVE-2026-64600HIGH7.8In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling I...
CVE-2026-63226MEDIUM6.9Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port for...
CVE-2026-6390MEDIUM6.8A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one ...
CVE-2026-7120MEDIUM5.3@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the ...
CVE-2026-15074HIGH7.5@fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the...
CVE-2026-21723MEDIUM5.3The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates ...
CVE-2026-16653MEDIUM5.5A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the ...
CVE-2026-16632HIGH7.3A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the lib...
CVE-2026-16631MEDIUM5.3A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/p...
CVE-2026-61246HIGH8.8Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...
CVE-2026-60455HIGH8.8Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now