2026 CVE Vulnerabilities

64,909 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-21092MEDIUM5.3Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system s...
CVE-2026-21086MEDIUM4.8Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configurat...
CVE-2026-21085MEDIUM6.7Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out...
CVE-2026-19945MEDIUM6.4The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in ...
CVE-2026-11821MEDIUM5.4The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to a...
CVE-2026-81647MEDIUM5.3Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affec...
CVE-2026-81646MEDIUM5.9Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affec...
CVE-2026-81644MEDIUM4.3DoS vulnerability in the preview service module. Impact: Successful exploitation of this vulnerability may affect availa...
CVE-2026-7804MEDIUM6.1The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '...
CVE-2026-77187MEDIUM6.4The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'before...
CVE-2026-77186MEDIUM6.4The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fallba...
CVE-2026-75966MEDIUM6.4The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'episode_contributor...
CVE-2026-57825MEDIUM5.7In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishan...
CVE-2026-49313MEDIUM5.5Permission control vulnerability in the app lock module. Impact: Successful exploitation of this vulnerability may affec...
CVE-2026-49312MEDIUM4Permission control vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect ...
CVE-2026-49311MEDIUM6.2Permission control vulnerability in the event notification module.Impact: Successful exploitation of this vulnerability ...
CVE-2026-49309MEDIUM4.8Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affec...
CVE-2026-41987MEDIUM6.2Permission control vulnerability in the app management module. Impact: Successful exploitation of this vulnerability may...
CVE-2026-19944MEDIUM4.9The WP Crowdfunding plugin for WordPress is vulnerable to generic SQL Injection via 'wpneo_reward' Post Meta in all vers...
CVE-2026-19800MEDIUM4.9The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to...
CVE-2026-19797MEDIUM6.1The User Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_group_section'...
CVE-2026-11363MEDIUM6.6The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injectio...
CVE-2026-87073MEDIUM6.5Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87048MEDIUM5.4Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87047MEDIUM6.3Tanium addressed an improper access controls vulnerability in Comply.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now