2026 CVE Vulnerabilities

61,679 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-36229Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2026-11441MEDIUM6.3A vulnerability was identified in theonedev onedev up to 15.0.5. This vulnerability affects the function canAccessIssue ...
CVE-2026-11440MEDIUM6.3A vulnerability was determined in theonedev onedev up to 15.0.5. This affects an unknown part of the file /repositories/...
CVE-2026-11439MEDIUM6.3A vulnerability was found in theonedev onedev up to 15.0.5. Affected by this issue is some unknown functionality of the ...
CVE-2026-11438MEDIUM6.3A vulnerability has been found in theonedev onedev up to 15.0.5. Affected by this vulnerability is an unknown functional...
CVE-2026-11437HIGH7.3A flaw has been found in perfree go-fastdfs-web up to 1.3.7. Affected is the function checkServer of the file /install/c...
CVE-2026-11436MEDIUM4.3A vulnerability was detected in Mage AI up to 0.9.79. This impacts the function useMutation of the file mage_ai/frontend...
CVE-2026-11435HIGH7.3A security vulnerability has been detected in Jinher OA 1.0. This affects an unknown function of the file nextselectplan...
CVE-2026-11434LOW2.4A weakness has been identified in FluentCMS 0.0.5. The impacted element is an unknown function of the file /admin/blocks...
CVE-2026-11413HIGH8.8A security vulnerability has been detected in JingDong JD Cloud Box AX6600 4.5.3.r4546. The impacted element is the func...
CVE-2026-11412MEDIUM6.3A weakness has been identified in Jinher OA C6. The affected element is an unknown function of the file /C6/JHSoft.Web.M...
CVE-2026-11411MEDIUM4.4A security flaw has been discovered in iAI Lab PDF AI App 4.21.0 on Android. Impacted is the function getExternalCacheDi...
CVE-2026-11408MEDIUM6.3A vulnerability was identified in vertex-app vertex up to 2026.02.12. This issue affects some unknown processing of the ...
CVE-2026-11406MEDIUM6.3A vulnerability was determined in GL.iNet MT3000 up to 4.4.5. This vulnerability affects unknown code of the file ovpncl...
CVE-2026-10725HIGH7.5Protocol::HTTP2 versions before 1.13 for Perl is vulnerable to a HTTP/2 Bomb. Protocol::HTTP2's inbound HPACK path has ...
CVE-2026-9851HIGH7.2The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, a...
CVE-2026-9829MEDIUM6.5The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injectio...
CVE-2026-9594MEDIUM4.4The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnera...
CVE-2026-9016MEDIUM5.3The Debug Log Manager – Conveniently Monitor and Inspect Errors plugin for WordPress is vulnerable to Improper Output Ne...
CVE-2026-8839MEDIUM5.3The MapPress Maps for WordPress plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key i...
CVE-2026-8611MEDIUM4.3The Klamra Paycal for Aspaclaria plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions ...
CVE-2026-7624MEDIUM4.3The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inc...
CVE-2026-9280MEDIUM6.1The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL ...
CVE-2026-9197MEDIUM4.9The Smart Slider 3 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.5.1...
CVE-2026-8991MEDIUM4.4The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Script...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now