2026 CVE Vulnerabilities

43,297 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-49332HIGH8.5A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X...
CVE-2026-42493HIGH7.5Addressing certain issues, in particular related to operations which may take excessively long and therefore would need ...
CVE-2026-42492HIGH7.5Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. To m...
CVE-2026-21047HIGH8.3Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitra...
CVE-2026-15025HIGH7.5The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to ...
CVE-2026-13440HIGH7.2The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for ...
CVE-2026-63301HIGH7In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding...
CVE-2026-59248HIGH8.7Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP...
CVE-2026-14785HIGH7.5The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all ver...
CVE-2026-14328HIGH8.8The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privil...
CVE-2026-10207HIGH7.5The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2....
CVE-2026-61376HIGH8.6ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings....
CVE-2026-59764HIGH8.6ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vu...
CVE-2026-14516HIGH7.5The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injec...
CVE-2026-14169HIGH8.1Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted in...
CVE-2026-14168HIGH8.8A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of th...
CVE-2026-14167HIGH8.8A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level inclu...
CVE-2026-13161HIGH7.5The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection vi...
CVE-2026-12800HIGH7.5The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code'...
CVE-2026-12741HIGH7.5The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via t...
CVE-2026-16585HIGH7.2The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbi...
CVE-2026-14924HIGH7.5The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in ...
CVE-2026-14870HIGH7.1The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and e...
CVE-2026-14490HIGH7.5The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory D...
CVE-2026-17524HIGH8.7Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path va...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now