2026 CVE Vulnerabilities

43,657 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-12391MEDIUM5An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) with...
CVE-2026-59249MEDIUM6.3Inconsistent interpretation of HTTP requests (HTTP response smuggling) vulnerability in elixir-mint mint allows a malici...
CVE-2026-35148MEDIUM6.3HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints ar...
CVE-2026-35146MEDIUM6.3HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish conn...
CVE-2026-6424MEDIUM6.7Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the syste...
CVE-2026-15727MEDIUM4.9The WP Bulk Delete plugin for WordPress is vulnerable to generic SQL Injection via the 'delete_user_roles' parameter in ...
CVE-2026-15651MEDIUM4.9The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' para...
CVE-2026-15610MEDIUM4.3The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorizatio...
CVE-2026-15407MEDIUM4.3The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7...
CVE-2026-15350MEDIUM4.3The The Cache Purger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2....
CVE-2026-15324MEDIUM4.4The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to St...
CVE-2026-15106MEDIUM5.3The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorizatio...
CVE-2026-15099MEDIUM6.4The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute ...
CVE-2026-15022MEDIUM6.5The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Sto...
CVE-2026-15021MEDIUM6.4The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all v...
CVE-2026-13767MEDIUM6.5The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, an...
CVE-2026-13755MEDIUM6.4The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_...
CVE-2026-13754MEDIUM6.5The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' param...
CVE-2026-12979MEDIUM5.5The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a t...
CVE-2026-12869MEDIUM6.1The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capability for ...
CVE-2026-12684MEDIUM6.5The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or non...
CVE-2026-12510MEDIUM5.9The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a c...
CVE-2026-12395MEDIUM6.5The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a ...
CVE-2026-11866MEDIUM5.4The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing a...
CVE-2026-11371MEDIUM6.1The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now