2026 CVE Vulnerabilities

64,858 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-90513MEDIUM6.5A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue ...
CVE-2026-90511MEDIUM6.3A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerabil...
CVE-2026-90507MEDIUM6.3A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is th...
CVE-2026-90506MEDIUM5A vulnerability was determined in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This impacts a...
CVE-2026-90505MEDIUM5A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This affects the fu...
CVE-2026-90501MEDIUM6.3A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.u...
CVE-2026-90500MEDIUM6.3A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload of...
CVE-2026-90499MEDIUM5.4A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This affects the function HrInfoController.updatePass of ...
CVE-2026-90496MEDIUM4.7A vulnerability was found in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_orde...
CVE-2026-88995MEDIUM5.3The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned...
CVE-2026-88912MEDIUM4.2The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changin...
CVE-2026-88764MEDIUM5.4The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal pay...
CVE-2026-80072MEDIUM4.7The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-login redi...
CVE-2026-77773MEDIUM5.3The Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8 does not perform any capability, ...
CVE-2026-90679MEDIUM4.3Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity int...
CVE-2026-90494MEDIUM5.3A flaw has been found in restify node-restify up to 12.0.0. This affects the function serveStatic in the library /lib/pl...
CVE-2026-90492MEDIUM6.3A security vulnerability has been detected in webgjc web_robot 2.4.0/2.5.0/2.8.0. The affected element is the function c...
CVE-2026-90491MEDIUM6.3A weakness has been identified in sanjevirau gsubs up to 1.0.3. Impacted is the function showQuerySuccessPage of the fil...
CVE-2026-90490MEDIUM6.3A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This issue affects some unknown processing of the compone...
CVE-2026-90488MEDIUM6.3A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass of...
CVE-2026-90487MEDIUM4.3A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the fi...
CVE-2026-90486MEDIUM6.3A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by th...
CVE-2026-90485MEDIUM5.5A flaw has been found in IOBit Uninstaller 15.5.0.11. Affected by this issue is the function sub_11838 of the file IUReg...
CVE-2026-90557MEDIUM6.1Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processin...
CVE-2026-90555MEDIUM6.5vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authentic...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now