2026 CVE Vulnerabilities

56,974 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-12492CRITICAL9.8The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actu...
CVE-2026-12395MEDIUM6.5The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a ...
CVE-2026-11866MEDIUM5.4The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing a...
CVE-2026-11371MEDIUM6.1The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and...
CVE-2026-53366HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on the paged allocation p...
CVE-2026-15458MEDIUM4.9The SEO Booster plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_field' parameter in all versio...
CVE-2026-15445MEDIUM4.9The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versio...
CVE-2026-15306MEDIUM6.1The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflec...
CVE-2026-15013CRITICAL9.8The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algor...
CVE-2026-13042HIGH7.2The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions...
CVE-2026-21729HIGH7.5Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depe...
CVE-2026-15652MEDIUM6.4The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2026-15336MEDIUM4.3The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and includin...
CVE-2026-14987MEDIUM6.4The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2026-13005MEDIUM4.4The MxChat – AI Chatbot & Content Generation for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scrip...
CVE-2026-12941MEDIUM6.5The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to generi...
CVE-2026-12753HIGH7.5The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Inject...
CVE-2026-12434MEDIUM4.3The List category posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and ...
CVE-2026-12409MEDIUM4.3The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress i...
CVE-2026-48863HIGH7.5A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to...
CVE-2026-3842HIGH7.8A flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine to write data beyond...
CVE-2026-23538HIGH7.5A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote attackers to establi...
CVE-2026-1609HIGH8.1A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user ac...
CVE-2026-15909MEDIUM6.3A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is a...
CVE-2026-15907HIGH7.3A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now