2026 CVE Vulnerabilities

64,982 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-86217MEDIUM5.3A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function ...
CVE-2026-86216MEDIUM4.3A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0. This impacts an un...
CVE-2026-86215MEDIUM4.3A vulnerability was identified in Mstfakts College-Management-System. The affected element is an unknown function of the...
CVE-2026-86258MEDIUM5.9nbviewer through 1.0.1 contains a path traversal vulnerability in LocalFileHandler.can_show() that uses string-prefix co...
CVE-2026-86257MEDIUM5.4wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gy...
CVE-2026-86256MEDIUM5.4wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/cor...
CVE-2026-86255MEDIUM6.5wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create ro...
CVE-2026-86254MEDIUM6.8wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views ret...
CVE-2026-86253MEDIUM5.9h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic(). On Node.js deployments...
CVE-2026-86252MEDIUM5.3h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing a...
CVE-2026-86251MEDIUM5.9h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility. A double-decoding flaw allo...
CVE-2026-86212MEDIUM4.3A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME....
CVE-2026-86205MEDIUM5.4h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to saniti...
CVE-2026-80439MEDIUM4.8The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted fo...
CVE-2026-80437MEDIUM4.8The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from b...
CVE-2026-19862MEDIUM4.8The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources...
CVE-2026-19859MEDIUM6.5The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message ...
CVE-2026-86183MEDIUM5.3A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmF...
CVE-2026-86182MEDIUM4.3A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dm...
CVE-2026-86179MEDIUM5.3A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Exp...
CVE-2026-86172MEDIUM6.3A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customer...
CVE-2026-86171MEDIUM6.3A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /mo...
CVE-2026-85038MEDIUM5.3The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin ...
CVE-2026-84028MEDIUM6.8The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting...
CVE-2026-75793MEDIUM6.5The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now