2026 CVE Vulnerabilities

56,936 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-63734MEDIUM6.9SurrealDB versions before 3.2.0 contain a denial of service vulnerability in the SurrealML header parser that allows aut...
CVE-2026-63733MEDIUM6.5SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMIS...
CVE-2026-16254MEDIUM4.3A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can cause an o...
CVE-2026-16247HIGH7.3In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this proces...
CVE-2026-16246HIGH7.3In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows g...
CVE-2026-15813MEDIUM6.5A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The int...
CVE-2026-15588MEDIUM5.3A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` a...
CVE-2026-14448HIGH8.6An high privileged remote attacker can exploit an authenticated OS command injection vulnerability in the system_certifi...
CVE-2026-2445MEDIUM6.1The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encod...
CVE-2026-16242CRITICAL9.4A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was...
CVE-2026-13577HIGH8.2Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. Dan...
CVE-2026-9833HIGH7.1The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape...
CVE-2026-8825MEDIUM4.9The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning p...
CVE-2026-6656HIGH7.5Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the bu...
CVE-2026-16235CRITICAL9.8Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-...
CVE-2026-13432MEDIUM5.4The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing a...
CVE-2026-13156MEDIUM5.4The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it veri...
CVE-2026-13147CRITICAL9.1The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowi...
CVE-2026-13142HIGH8.1The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a wo...
CVE-2026-12973MEDIUM6.5The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation i...
CVE-2026-12972MEDIUM5.3The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation i...
CVE-2026-12970HIGH7.1The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attri...
CVE-2026-12898MEDIUM6.5The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value be...
CVE-2026-12724MEDIUM4.3The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a re...
CVE-2026-12723MEDIUM5.3The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing u...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now