2026 CVE Vulnerabilities

64,889 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-86777MEDIUM5.3AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authorize access to the GET /api/nodes endpoint, allowing...
CVE-2026-86547MEDIUM6.2mrubyc through 4.0.0 contains a null pointer dereference vulnerability in the op_enter() handler in src/vm.c when proces...
CVE-2026-78377MEDIUM6.1URL redirection to untrusted site ('open redirect') vulnerability in Yordam Informatics Technology Consulting, Training,...
CVE-2026-19733MEDIUM5.3Server-Side request forgery (SSRF) vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic S...
CVE-2026-11838MEDIUM4.3Missing authentication for critical function vulnerability in Yordam Informatics Technology Consulting, Training, and El...
CVE-2026-79974MEDIUM6.4Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-79973MEDIUM6.3Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-79967MEDIUM5.6Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-79640MEDIUM5.4Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-80177MEDIUM6.5Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-80124MEDIUM5.5Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-80055MEDIUM4.4Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-19778MEDIUM6.5The WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping plugin for WordPress is vulnera...
CVE-2026-19729MEDIUM4.9A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Ha...
CVE-2026-17149MEDIUM6.4The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress ...
CVE-2026-15398MEDIUM4.3The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to a...
CVE-2026-87747MEDIUM4.9The Enterprise Cloud Database developed by Ragic has an Arbitrary File Read vulnerability. Privileged remote attackers c...
CVE-2026-85117MEDIUM6.5The Contact Form 7 Captcha WordPress plugin before 0.1.9 runs the shortcode parser over the whole rendered Contact Form ...
CVE-2026-83537MEDIUM5.3The WP Express Checkout WordPress plugin before 2.5.0 does not verify server-side that a payment was actually completed ...
CVE-2026-80440MEDIUM4.8The Hustle WordPress plugin before 7.8.14.2 does not prevent shortcodes in submitted form values from being executed whe...
CVE-2026-19855MEDIUM6.5The CleanTalk WordPress plugin before 6.87 does not prevent unauthenticated, user-supplied comment content from being pa...
CVE-2026-19802MEDIUM4.3The Checkout Custom Fields Builder for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all ver...
CVE-2026-8615MEDIUM4.3The Reviso Exporter for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2026-85418MEDIUM5.4The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.9...
CVE-2026-85133MEDIUM5.4The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on several of its set...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now