2026 CVE Vulnerabilities

67,127 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-11744LOW3.8An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices. The application fa...
CVE-2026-97177MEDIUM6.6A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are en...
CVE-2026-97176MEDIUM4.2A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management sol...
CVE-2026-97168——Rejected reason: it is a suggestion
CVE-2026-93662MEDIUM4.3The Events Manager WordPress plugin before 7.4.5 does not force the scope of its logged-in event and location search wh...
CVE-2026-93661LOW2.7The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers o...
CVE-2026-89005MEDIUM6.8The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configura...
CVE-2026-89004LOW2.7The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returnin...
CVE-2026-89002MEDIUM6.8The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a u...
CVE-2026-88847MEDIUM4.3The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course...
CVE-2026-88846MEDIUM5.3The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled...
CVE-2026-88845MEDIUM4.3The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on ...
CVE-2026-88843HIGH7.2The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings...
CVE-2026-84151LOW3.5The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own m...
CVE-2026-82850MEDIUM4.3The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticate...
CVE-2026-82849MEDIUM4.3The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progre...
CVE-2026-82195MEDIUM6.5The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret...
CVE-2026-80513HIGH7.5The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes ...
CVE-2026-80338MEDIUM6.8The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users...
CVE-2026-74991MEDIUM6.8The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form su...
CVE-2026-14780HIGH7.5A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization ...
CVE-2026-97155MEDIUM6.5Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension v...
CVE-2026-97152HIGH8.6Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport...
CVE-2026-97151HIGH8.4mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a documen...
CVE-2026-96898HIGH7.3A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected by this vulnerability is an unknown functionality...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now