2026 CVE Vulnerabilities

65,801 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-97228LOW2.7Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status com...
CVE-2026-27867MEDIUM4.8An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration actio...
CVE-2026-97898HIGH8.4Insecure Direct Object Reference / missing object-level authorization in the Akia keyless entry cloud service. The unloc...
CVE-2026-92106LOW2.3Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dashbitco lazy_htm...
CVE-2026-97863MEDIUM6.3The cisco_firesight_manager_ACL_rule_export module in misp-modules generates a shell script (.sh) that authenticates to ...
CVE-2026-92573MEDIUM6.5Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message d...
CVE-2026-92564HIGH7.5A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of...
CVE-2026-92560HIGH7.5A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential...
CVE-2026-92550HIGH7.5A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential...
CVE-2026-88848MEDIUM4.2The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50 does not verify that a course a member asks to enrol in is c...
CVE-2026-86837MEDIUM5.3The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored deta...
CVE-2026-80514MEDIUM5.3The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address heade...
CVE-2026-6088MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-6087MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-6086MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-6085MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-6084MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-6083MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-6082MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-96752HIGH7.2The Zero Spam for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Nested POST Array Keys...
CVE-2026-96568HIGH7.2The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_n...
CVE-2026-96448MEDIUM6.6A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management ...
CVE-2026-95866HIGH7.2The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v...
CVE-2026-95864HIGH7.2The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'css[fonts]' Parameter in all ...
CVE-2026-94573HIGH7.2The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater F...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now