2026 CVE Vulnerabilities

67,127 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-3253MEDIUM4.3The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized modification of data due to ...
CVE-2026-19532MEDIUM5.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HAVELSAN Inc. Liman MYS ...
CVE-2026-16302MEDIUM4.3The Spectra Legacy – Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio...
CVE-2026-97179MEDIUM4.3A security vulnerability has been detected in O2OA up to 9.5.3/10.0.2. This vulnerability affects the function list of t...
CVE-2026-79680MEDIUM4.5Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. An attacker us...
CVE-2026-4638HIGH7.1PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Script sensor that multiplies two integer parameters ...
CVE-2026-92905MEDIUM5.3ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a DoS vulnerability that allowe...
CVE-2026-57590HIGH8.1A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not...
CVE-2026-4637MEDIUM5.1Paessler PRTG Network Monitor before version 26.2.120.1449 is affected by a reflected Cross-Site Scripting (XSS) vulnera...
CVE-2026-18335MEDIUM5.4The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Blind Server-Side ...
CVE-2026-15731MEDIUM6.4The WP Multilang – Translation and Multilingual Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2026-12227CRITICAL9.8The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, an...
CVE-2026-97185HIGH7.8A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly ...
CVE-2026-85682HIGH8.8The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10....
CVE-2026-78313MEDIUM6.5Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-78312CRITICAL9.1Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-78311HIGH8.8SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-78310MEDIUM4.3Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-78309HIGH8.8SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-78308CRITICAL9.8Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before...
CVE-2026-77193HIGH7.5The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and ...
CVE-2026-97181MEDIUM5.3GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can direct...
CVE-2026-87739MEDIUM6.9An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report ...
CVE-2026-82077HIGH7.3An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax compone...
CVE-2026-81645MEDIUM5.9Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availa...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now