2026 CVE Vulnerabilities

55,748 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56392LOW1.8GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation...
CVE-2026-56391MEDIUM4.6GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--ch...
CVE-2026-49745HIGH7.8Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ...
CVE-2026-49744HIGH7.8Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ...
CVE-2026-49743HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of...
CVE-2026-24727CRITICAL9.3An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporat...
CVE-2026-15821MEDIUM6.4The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2026-15739MEDIUM6.4The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' ...
CVE-2026-15704CRITICAL9.8In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authori...
CVE-2026-15346MEDIUM6.1The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '...
CVE-2026-12702MEDIUM4.9In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to...
CVE-2026-16910MEDIUM5.5A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers acc...
CVE-2026-16519HIGH7.3A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads on...
CVE-2026-15755MEDIUM6.4The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Short...
CVE-2026-15665MEDIUM6.4The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2026-15653MEDIUM6.4The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2026-15648MEDIUM6.4The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attri...
CVE-2026-15464MEDIUM6.4The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Att...
CVE-2026-15334MEDIUM6.4The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress...
CVE-2026-15333MEDIUM6.4The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress...
CVE-2026-12654MEDIUM5.3The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up...
CVE-2026-14603HIGH7.5The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint...
CVE-2026-14172HIGH7.8Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without ...
CVE-2026-12981HIGH7.5The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user pas...
CVE-2026-12877CRITICAL9.1The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user s...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now