2026 CVE Vulnerabilities

56,900 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-1372MEDIUM4.3The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and in...
CVE-2026-15370HIGH7.3A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concaten...
CVE-2026-15145MEDIUM6.4The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored ...
CVE-2026-8593MEDIUM5.3Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, ...
CVE-2026-3183HIGH7.1Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass.
CVE-2026-8082HIGH7.5The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQ...
CVE-2026-14185MEDIUM4.3The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-...
CVE-2026-14184MEDIUM5.4The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of...
CVE-2026-14183MEDIUM4.3The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt han...
CVE-2026-13694MEDIUM6.5The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated tr...
CVE-2026-13693MEDIUM5.9The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the ...
CVE-2026-11767HIGH8.8The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values bef...
CVE-2026-3182MEDIUM4.3Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive ...
CVE-2026-16266MEDIUM6.3Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in ...
CVE-2026-15927MEDIUM6.8A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints...
CVE-2026-15812MEDIUM4.8A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). ...
CVE-2026-15811MEDIUM5.8A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not...
CVE-2026-15782MEDIUM4.9The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPres...
CVE-2026-13439CRITICAL9.8The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Admin...
CVE-2026-15156MEDIUM6.4The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored ...
CVE-2026-59776HIGH7Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the v...
CVE-2026-16336MEDIUM5.3A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/jav...
CVE-2026-6952HIGH7.2A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B...
CVE-2026-63729MEDIUM6.8The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince co...
CVE-2026-16334MEDIUM6.3A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code o...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now