2026 CVE Vulnerabilities

64,868 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-78172MEDIUM6.1The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query ...
CVE-2026-77150MEDIUM6.1The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data[name...
CVE-2026-19985MEDIUM6.1The Relevanssi – A Better Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,...
CVE-2026-18964MEDIUM6.1The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plu...
CVE-2026-18562MEDIUM6.1The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scri...
CVE-2026-12215MEDIUM5.3The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in ...
CVE-2026-11496MEDIUM6.5The Woo PDF Invoice Builder plugin (also distributed as "PDF Builder for WooCommerce") for WordPress is vulnerable to In...
CVE-2026-11446MEDIUM5.3The Booktics – Booking Calendar for Appointments and Service Businesses plugin for WordPress is vulnerable to unauthoriz...
CVE-2026-89145MEDIUM4.2Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape plugin directory names in the dependency error pag...
CVE-2026-89092MEDIUM4.2The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server retur...
CVE-2026-88914MEDIUM4.4A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file cont...
CVE-2026-78129MEDIUM5.9strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.
CVE-2026-78126MEDIUM5.9strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.
CVE-2026-78123MEDIUM5.9strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.
CVE-2026-84941MEDIUM6.9An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an aut...
CVE-2026-81906MEDIUM6.3Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-valid...
CVE-2026-81905MEDIUM6.3Concrete CMS below 9.5.3 stores user validation hashes for multiple purposes (email/registration validation, password re...
CVE-2026-18121MEDIUM6.3Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endp...
CVE-2026-16172MEDIUM6Netskope was notified of an out-of-bounds heap read affecting the Endpoint DLP (EPDLP) service of the Netskope Client. A...
CVE-2026-86087MEDIUM4.3IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted r...
CVE-2026-82100MEDIUM6.5IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due...
CVE-2026-82092MEDIUM6.5IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information ...
CVE-2026-81554MEDIUM6.5IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information ...
CVE-2026-80434MEDIUM5IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and...
CVE-2026-80378MEDIUM6.5IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now