2026 CVE Vulnerabilities

55,906 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-13009MEDIUM6.5The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Param...
CVE-2026-52688HIGH7.5RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
CVE-2026-52686LOW3.7The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signat...
CVE-2026-52684LOW3.7If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data...
CVE-2026-16723CRITICAL9A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable ...
CVE-2026-16287HIGH7.8Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILG...
CVE-2026-9729MEDIUM6.4The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_noti...
CVE-2026-9713HIGH7.5The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table'...
CVE-2026-9635MEDIUM6.4The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parame...
CVE-2026-59678HIGH7.1An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary fi...
CVE-2026-59677MEDIUM6.8A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined ...
CVE-2026-12421HIGH7.2The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all version...
CVE-2026-9577MEDIUM4.8The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before ref...
CVE-2026-9066MEDIUM6.1The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asse...
CVE-2026-59676MEDIUM5.8A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user ...
CVE-2026-14291HIGH7.5The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its ...
CVE-2026-12082HIGH7.5The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes...
CVE-2026-7534HIGH7.2The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST AP...
CVE-2026-7232HIGH7.2The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in ...
CVE-2026-64600HIGH7.8In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling I...
CVE-2026-63226MEDIUM6.9Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port for...
CVE-2026-6390MEDIUM6.8A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one ...
CVE-2026-7120MEDIUM5.3@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the ...
CVE-2026-15074HIGH7.5@fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the...
CVE-2026-21723MEDIUM5.3The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now