2026 CVE Vulnerabilities

43,564 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-14185MEDIUM4.3The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-...
CVE-2026-14184MEDIUM5.4The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of...
CVE-2026-14183MEDIUM4.3The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt han...
CVE-2026-13694MEDIUM6.5The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated tr...
CVE-2026-13693MEDIUM5.9The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the ...
CVE-2026-3182MEDIUM4.3Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive ...
CVE-2026-16266MEDIUM6.3Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in ...
CVE-2026-15927MEDIUM6.8A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints...
CVE-2026-15812MEDIUM4.8A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). ...
CVE-2026-15811MEDIUM5.8A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not...
CVE-2026-15782MEDIUM4.9The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPres...
CVE-2026-15156MEDIUM6.4The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored ...
CVE-2026-16336MEDIUM5.3A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/jav...
CVE-2026-63729MEDIUM6.8The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince co...
CVE-2026-16334MEDIUM6.3A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code o...
CVE-2026-64626MEDIUM6.4AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the en...
CVE-2026-57852MEDIUM6.3Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote att...
CVE-2026-51385MEDIUM6.9An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code v...
CVE-2026-51025MEDIUM6.1Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary...
CVE-2026-47144MEDIUM5.5Shamefile is a linter for undocumented linter warnings. Prior to version 0.1.7, a path traversal vulnerability in `shame...
CVE-2026-47134MEDIUM6.9ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. The ECDSA private k...
CVE-2026-47133MEDIUM6.9ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 5....
CVE-2026-47128MEDIUM6.1nono is software that allows users to run AI agents in a zero-latency sandbox. Prior to version 0.55.0, the nono Landloc...
CVE-2026-12900MEDIUM6.4The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2026-64651MEDIUM6.3The `@ai-sdk/harness-opencode` tool connects HarnessAgent to OpenCode through a sandboxed bridge. Prior to version 1.0.2...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now