2026 CVE Vulnerabilities

44,807 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-21063MEDIUM6.8Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers t...
CVE-2026-64940HIGH8.8Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular exp...
CVE-2026-57279MEDIUM6.8Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may...
CVE-2026-21062MEDIUM4.8Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard d...
CVE-2026-21061MEDIUM6Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM relate...
CVE-2026-21060MEDIUM6.7Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data a...
CVE-2026-21059MEDIUM6.9Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attac...
CVE-2026-21058MEDIUM6.9Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with...
CVE-2026-19089CRITICAL9.8The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its ac...
CVE-2026-19077MEDIUM6.5The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and d...
CVE-2026-19075MEDIUM5All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any ...
CVE-2026-19074MEDIUM5.3The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) i...
CVE-2026-19053CRITICAL9.1The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQ...
CVE-2026-19049HIGH8.6The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries,...
CVE-2026-18960MEDIUM5.4The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, al...
CVE-2026-18946HIGH7.5The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded thr...
CVE-2026-18934MEDIUM5.5The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or is allowed ...
CVE-2026-18786HIGH8.8The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and ...
CVE-2026-18666MEDIUM4.3The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter befor...
CVE-2026-18470HIGH7.5The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the a...
CVE-2026-18469HIGH8.1The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a se...
CVE-2026-18468HIGH8.1The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the acc...
CVE-2026-18200MEDIUM4.3The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user ...
CVE-2026-18030HIGH8.1The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password...
CVE-2026-17542HIGH7.5The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connecto...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now