2026 CVE Vulnerabilities

64,868 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-89179MEDIUM4.3WeenyGenius, a computer lab management system by Howyar Technologies, has a Missing Support for Integrity Check vulnerab...
CVE-2026-89175MEDIUM5.3Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability...
CVE-2026-89173MEDIUM5.3Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. U...
CVE-2026-6642MEDIUM6.4The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset e...
CVE-2026-6641MEDIUM6.4The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shor...
CVE-2026-6640MEDIUM6.4The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attribut...
CVE-2026-86815MEDIUM5.5The BackWPup WordPress plugin before 5.7.5 does not properly restrict access to several of its REST API routes for job,...
CVE-2026-86812MEDIUM6.5The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoint...
CVE-2026-86782MEDIUM5.5The Visualizer WordPress plugin before 4.0.6 does not properly authorise access to its chart-building actions, allowing...
CVE-2026-86781MEDIUM5.3The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or ...
CVE-2026-86780MEDIUM6.8The Featured Image with URL WordPress plugin before 1.0.6 does not sanitise and escape a stored image attribute value be...
CVE-2026-85678MEDIUM6.8The AI Builder WordPress plugin before 2.7.8 does not sanitise custom JavaScript saved against a post before echoing it...
CVE-2026-83546MEDIUM6.8The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML ...
CVE-2026-83545MEDIUM6.8The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside a...
CVE-2026-82305MEDIUM5.3The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given...
CVE-2026-14566MEDIUM4.3The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce chec...
CVE-2026-14565MEDIUM5.4The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce chec...
CVE-2026-14562MEDIUM5.3The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks bef...
CVE-2026-13326MEDIUM6.9An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial ...
CVE-2026-89169MEDIUM4.1live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .ver...
CVE-2026-89160MEDIUM6.5PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF su...
CVE-2026-89158MEDIUM6.5PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.
CVE-2026-89156MEDIUM5.9PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF da...
CVE-2026-84960MEDIUM6.1The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Query Stri...
CVE-2026-7438MEDIUM6.4The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subti...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now