2026 CVE Vulnerabilities

64,858 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-81911MEDIUM5.4Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot dialog. The custom_slot save_templ...
CVE-2026-79035MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0...
CVE-2026-78547MEDIUM4.4Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. This issue affects Citrix Workspace app f...
CVE-2026-78546MEDIUM4.8Out-of-bounds read vulnerability in Citirx Workspace app for Windows. This issue affects Workspace app for Windows: bef...
CVE-2026-77490MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) ...
CVE-2026-68526MEDIUM4.3Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concret...
CVE-2026-49463MEDIUM6.5NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, custom...
CVE-2026-49462MEDIUM5.3NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, custom...
CVE-2026-89329MEDIUM6.2A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this ...
CVE-2026-81910MEDIUM6.5Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated ...
CVE-2026-62140MEDIUM5.3Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions.
CVE-2026-62139MEDIUM4.3Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions.
CVE-2026-62138MEDIUM6.5Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions.
CVE-2026-62137MEDIUM5.3Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 versions.
CVE-2026-62136MEDIUM5.3Unauthenticated Broken Access Control in Flexible Quantity – Measurement Price Calculator for WooCommerce <= 2.3.21 vers...
CVE-2026-62135MEDIUM5.3Unauthenticated Broken Access Control in Booktics <= 1.0.24 versions.
CVE-2026-62134MEDIUM4.3Contributor Insecure Direct Object References (IDOR) in Starter Templates <= 4.7.5 versions.
CVE-2026-62133MEDIUM5.4Subscriber Cross Site Request Forgery (CSRF) in RTMKit <= 2.1.5 versions.
CVE-2026-62132MEDIUM5.3Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions.
CVE-2026-62114MEDIUM5.3Unauthenticated Broken Access Control in Passster <= 4.3.13 versions.
CVE-2026-62113MEDIUM4.3Contributor Insecure Direct Object References (IDOR) in Slim SEO <= 4.10.0 versions.
CVE-2026-62111MEDIUM6.5Contributor Cross Site Scripting (XSS) in Simple Payment <= 2.5.4 versions.
CVE-2026-62110MEDIUM6.5Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions.
CVE-2026-62088MEDIUM5.3Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows Retrieve Embedded Sensitive ...
CVE-2026-27378MEDIUM5.3Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now