2026 CVE Vulnerabilities

43,308 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-66729HIGH8.7facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows u...
CVE-2026-24252HIGH7.8NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of...
CVE-2026-17192HIGH8.5A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authentica...
CVE-2026-66399HIGH8.5phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows admi...
CVE-2026-66397HIGH8.6phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, al...
CVE-2026-59251HIGH7.5Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthentica...
CVE-2026-59250HIGH8.3Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corru...
CVE-2026-58227HIGH7.5The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a ...
CVE-2026-55953HIGH7.4The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in...
CVE-2026-55737HIGH7.5Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can ...
CVE-2026-54890HIGH7.5Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modu...
CVE-2026-42792HIGH7.5Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote att...
CVE-2026-66427HIGH7.6Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.
CVE-2026-66050HIGH8.7NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows una...
CVE-2026-59558HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
CVE-2026-59556HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.
CVE-2026-59553HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.
CVE-2026-59552HIGH7.2Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer &amp; Embedder <= 1.4.2 versions.
CVE-2026-59551HIGH8.5Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
CVE-2026-59548HIGH7.5Unauthenticated Sensitive Data Exposure in Byteflows Travel &amp; Hotel Booking <= 1.0.0 versions.
CVE-2026-59546HIGH7.4Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.
CVE-2026-59539HIGH7.5Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.
CVE-2026-59537HIGH7.6Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versio...
CVE-2026-59536HIGH7.5Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
CVE-2026-59535HIGH7.3Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now