2026 CVE Vulnerabilities

67,167 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15731MEDIUM6.4The WP Multilang – Translation and Multilingual Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2026-12227CRITICAL9.8The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, an...
CVE-2026-97185HIGH7.8A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly ...
CVE-2026-85682HIGH8.8The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10....
CVE-2026-78313MEDIUM6.5Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-78312CRITICAL9.1Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-78311HIGH8.8SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-78310MEDIUM4.3Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-78309HIGH8.8SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-78308CRITICAL9.8Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before...
CVE-2026-77193HIGH7.5The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and ...
CVE-2026-97181MEDIUM5.3GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can direct...
CVE-2026-87739MEDIUM6.9An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report ...
CVE-2026-82077HIGH7.3An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax compone...
CVE-2026-81645MEDIUM5.9Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availa...
CVE-2026-11744LOW3.8An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices. The application fa...
CVE-2026-97177MEDIUM6.6A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are en...
CVE-2026-97176MEDIUM4.2A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management sol...
CVE-2026-97168——Rejected reason: it is a suggestion
CVE-2026-93662MEDIUM4.3The Events Manager WordPress plugin before 7.4.5 does not force the scope of its logged-in event and location search wh...
CVE-2026-93661LOW2.7The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers o...
CVE-2026-89005MEDIUM6.8The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configura...
CVE-2026-89004LOW2.7The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returnin...
CVE-2026-89002MEDIUM6.8The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a u...
CVE-2026-88847MEDIUM4.3The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now