2026 CVE Vulnerabilities

43,284 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-13395HIGH8.6The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a ...
CVE-2026-13178HIGH7.5The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied ...
CVE-2026-12687HIGH7.5The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into th...
CVE-2026-12500HIGH7.5The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a...
CVE-2026-67248HIGH8.8A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because ...
CVE-2026-67245HIGH8.1A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled...
CVE-2026-1360HIGH7.5The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and includ...
CVE-2026-14356HIGH8.8The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2....
CVE-2026-67244HIGH7.2A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user...
CVE-2026-48448HIGH8.6Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL ...
CVE-2026-18188HIGH8.1A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled...
CVE-2026-18187HIGH8.1A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-control...
CVE-2026-18186HIGH8.1A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-contr...
CVE-2026-16727HIGH7.3Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows...
CVE-2026-15929HIGH7.1Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics Sma...
CVE-2026-18017HIGH8.8Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code insid...
CVE-2026-18012HIGH8.8Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-17995HIGH8.1Out of bounds read in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds...
CVE-2026-17993HIGH7Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalat...
CVE-2026-17989HIGH8.8Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside ...
CVE-2026-17979HIGH7.5Race in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox ...
CVE-2026-17971HIGH8.8Inappropriate implementation in Frame in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially p...
CVE-2026-17969HIGH8.8Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute a...
CVE-2026-17967HIGH8.8Use after free in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially...
CVE-2026-17956HIGH8.8Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now