2026 CVE Vulnerabilities

55,163 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6454MEDIUM6.4The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and inclu...
CVE-2026-15420MEDIUM4.3The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory ...
CVE-2026-15100MEDIUM6.4The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnore...
CVE-2026-13464MEDIUM5.3The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Ob...
CVE-2026-12736HIGH8The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This ...
CVE-2026-11922MEDIUM6.5A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST...
CVE-2026-11354MEDIUM5.3The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an...
CVE-2026-62825CRITICAL9.8Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-58275CRITICAL9.8Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56191CRITICAL10Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network...
CVE-2026-56167HIGH8.8Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network...
CVE-2026-56165CRITICAL9.8Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
CVE-2026-56160CRITICAL9.9Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a netwo...
CVE-2026-54120HIGH8.8Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
CVE-2026-50517CRITICAL9.9Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
CVE-2026-49159MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose ...
CVE-2026-35425HIGH7.2Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
CVE-2026-50044HIGH7.6Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an...
CVE-2026-44955MEDIUM6.9Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized contr...
CVE-2026-42933CRITICAL10Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow ...
CVE-2026-40430HIGH8.7Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cl...
CVE-2026-28698CRITICAL9.2Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized contr...
CVE-2026-16767MEDIUM6.5A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. This affects the function ZipFile::extractTo of the file sr...
CVE-2026-65694HIGH8.7Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthen...
CVE-2026-65604HIGH8.8Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) d...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now