2026 CVE Vulnerabilities

64,858 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-89252MEDIUM6.5AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to verify ownership in addLiveLink.php when updatin...
CVE-2026-89251MEDIUM6.5AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in plugin/AD_Server/log....
CVE-2026-89248MEDIUM5.3AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization check in plugi...
CVE-2026-89247MEDIUM6.1WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier contains an XML injection vulnerability in pl...
CVE-2026-89246MEDIUM5.4WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a CSV formula injection vulnerability in th...
CVE-2026-89245MEDIUM6.5WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability ...
CVE-2026-89244MEDIUM6.1WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerabil...
CVE-2026-89241MEDIUM6.1WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerabil...
CVE-2026-89240MEDIUM6.1WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerabil...
CVE-2026-89239MEDIUM6.1WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerabil...
CVE-2026-89148MEDIUM5.4AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an open redirect in objects/playlistSort.php. Be...
CVE-2026-86813MEDIUM4.8The MetForm WordPress plugin before 4.1.9 does not properly neutralize newline characters in user-submitted values that ...
CVE-2026-86809MEDIUM5.3The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to i...
CVE-2026-85116MEDIUM6.5The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over th...
CVE-2026-82215MEDIUM5.9The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3 does not verify the authenticity of the pa...
CVE-2026-82213MEDIUM5.3The Nexi XPay Build WordPress plugin from 7.6.1 to 7.6.2 does not verify that the saved payment token being requested be...
CVE-2026-77159MEDIUM5.5A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based ch...
CVE-2026-87859MEDIUM5.3morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField() function does n...
CVE-2026-87123MEDIUM5.9hbs is an Express view engine wrapper for Handlebars. Version 4.3.0 can crash the Node.js process during output escaping...
CVE-2026-87727MEDIUM6.9a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerability, which allows an unauthenticated attacker to ...
CVE-2026-89179MEDIUM4.3WeenyGenius, a computer lab management system by Howyar Technologies, has a Missing Support for Integrity Check vulnerab...
CVE-2026-89175MEDIUM5.3Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability...
CVE-2026-89173MEDIUM5.3Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. U...
CVE-2026-6642MEDIUM6.4The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset e...
CVE-2026-6641MEDIUM6.4The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shor...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now