2026 CVE Vulnerabilities

67,167 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-88846MEDIUM5.3The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled...
CVE-2026-88845MEDIUM4.3The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on ...
CVE-2026-88843HIGH7.2The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings...
CVE-2026-84151LOW3.5The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own m...
CVE-2026-82850MEDIUM4.3The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticate...
CVE-2026-82849MEDIUM4.3The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progre...
CVE-2026-82195MEDIUM6.5The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret...
CVE-2026-80513HIGH7.5The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes ...
CVE-2026-80338MEDIUM6.8The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users...
CVE-2026-74991MEDIUM6.8The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form su...
CVE-2026-14780HIGH7.5A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization ...
CVE-2026-97155MEDIUM6.5Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension v...
CVE-2026-97152HIGH8.6Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport...
CVE-2026-97151HIGH8.4mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a documen...
CVE-2026-96898HIGH7.3A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected by this vulnerability is an unknown functionality...
CVE-2026-96892MEDIUM4.3A flaw has been found in Edimax BR-6428nC 1.16. The impacted element is the function websRedirect of the component gofor...
CVE-2026-97149MEDIUM5.3In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempU...
CVE-2026-96891CRITICAL9.8A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel....
CVE-2026-96884MEDIUM6.3A security flaw has been discovered in MantisZip up to 0.4.5. Affected by this issue is the function Path.Combine of the...
CVE-2026-96882MEDIUM5.3A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1. Affected by this vulnerability is the functio...
CVE-2026-96881MEDIUM5.3A vulnerability was determined in TaleLin lin-cms-spring-boot up to 0.2.1. Affected is the function getBooks of the file...
CVE-2026-97056MEDIUM6.8SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the opaque session tokenizer (wh...
CVE-2026-97055HIGH8.1SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOK...
CVE-2026-96880MEDIUM5.3A vulnerability was found in TaleLin lin-cms-spring-boot up to 0.2.1. This impacts the function getBook of the file src/...
CVE-2026-96810LOW3.5A vulnerability was identified in huanzi-qch base-admin up to 52816b760cd53244989fd664bbb2b3d4edbfdbf1. This issue affec...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now