2026 CVE Vulnerabilities

53,578 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-63264MEDIUM5.3Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3 - The Joomla extension JoomShopping is vuln...
CVE-2026-2406MEDIUM6.5Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industr...
CVE-2026-15787MEDIUM6.4The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu ...
CVE-2026-63048CRITICAL9.4Joomla Extension - joomlack.fr - Improper access control in Page Builder CK 1.0.0-3.1.2, 3.4.0-3.4.11, 3.5.0-3.6.2 - The...
CVE-2026-63047HIGH7.5Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - ...
CVE-2026-45820HIGH7.5fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with ...
CVE-2026-3821HIGH8.8Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. An authorized attack...
CVE-2026-14322MEDIUM5.3The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created throug...
CVE-2026-12987HIGH7.5The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-Use...
CVE-2026-12968HIGH8.8The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthent...
CVE-2026-15802HIGH8.1The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation...
CVE-2026-56844HIGH8.4A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate ...
CVE-2026-16492MEDIUM5.5A weakness has been identified in umijs umi up to 4.6.63. The affected element is the function git.getFileCreateInfo of ...
CVE-2026-16490MEDIUM6.3A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of t...
CVE-2026-63263MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansio...
CVE-2026-63262MEDIUM4.3Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied ...
CVE-2026-16489MEDIUM5.3A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib...
CVE-2026-16488MEDIUM5A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Po...
CVE-2026-63261MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)...
CVE-2026-63260MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)...
CVE-2026-63259MEDIUM4.3Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplie...
CVE-2026-63145MEDIUM4.3Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification ...
CVE-2026-63144MEDIUM6.5Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request s...
CVE-2026-63143MEDIUM4.3Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122...
CVE-2026-63142MEDIUM5Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reportin...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now