2026 CVE Vulnerabilities

43,286 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-58180HIGH8.2The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affects Apache ...
CVE-2026-58178HIGH8.2The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects A...
CVE-2026-58175HIGH8.2Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0...
CVE-2026-58164HIGH8.3Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. This iss...
CVE-2026-58159HIGH8.2Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affect...
CVE-2026-58158HIGH8.2Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack. This issue affects A...
CVE-2026-58157HIGH8.7Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections. This i...
CVE-2026-50622HIGH8.8Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoi...
CVE-2026-23904HIGH7.3Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A re...
CVE-2026-65324HIGH8.2Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client ...
CVE-2026-64557HIGH8.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_...
CVE-2026-64556HIGH7.8In the Linux kernel, the following vulnerability has been resolved: perf/core: Detach event groups during remove_on_exe...
CVE-2026-58153HIGH8.3Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting H...
CVE-2026-58151HIGH8.7Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This ...
CVE-2026-13425HIGH7.2The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in al...
CVE-2026-35226HIGH7.1An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same n...
CVE-2026-33930HIGH8.2Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handl...
CVE-2026-18192HIGH7.1VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to e...
CVE-2026-63231HIGH8.1A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based...
CVE-2026-14300HIGH8.1The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bin...
CVE-2026-14234HIGH7.1The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowin...
CVE-2026-13690HIGH7.4The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor log...
CVE-2026-11974HIGH8.6The wp-media-folder-addon WordPress plugin before 4.1.7 does not validate a user-supplied parameter before using it in a...
CVE-2026-12476HIGH7.2The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3...
CVE-2026-12144HIGH8.8The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and incl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now