2026 CVE Vulnerabilities

64,803 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-74014CRITICAL9.9Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
CVE-2026-74001CRITICAL9.8Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
CVE-2026-73993CRITICAL9.8Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
CVE-2026-73992CRITICAL9.9Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
CVE-2026-68566CRITICAL9.3Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
CVE-2026-66682CRITICAL9.8Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
CVE-2026-66680CRITICAL9.3Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
CVE-2026-66672CRITICAL9.8Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.
CVE-2026-66649CRITICAL9.3Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
CVE-2026-66609CRITICAL9.3Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
CVE-2026-66600CRITICAL9.1Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.
CVE-2026-66593CRITICAL9.3Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
CVE-2026-66592CRITICAL9.3Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
CVE-2026-66583CRITICAL9.8Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
CVE-2026-14950CRITICAL9.8An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session aft...
CVE-2026-75860CRITICAL9.8The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its a...
CVE-2026-76886CRITICAL9.8C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76850CRITICAL9.8LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch...
CVE-2026-76590CRITICAL9.9A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionalit...
CVE-2026-76589CRITICAL9.9A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/my...
CVE-2026-76404CRITICAL9.1In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands...
CVE-2026-76312CRITICAL9.4In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hyperte...
CVE-2026-76311CRITICAL9.4In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded repo...
CVE-2026-76310CRITICAL9.4In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded repo...
CVE-2026-76584CRITICAL9.9A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some unknown functionali...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now