2026 CVE Vulnerabilities

43,937 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-15471MEDIUM4.3A vulnerability was found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/pci...
CVE-2026-15470MEDIUM4.3A vulnerability has been found in Eleveo Call Recording Software 9.7.0. Affected by this issue is some unknown functiona...
CVE-2026-10660MEDIUM6.4The Bluetooth BAP Broadcast Assistant GATT client in subsys/bluetooth/audio/bap_broadcast_assistant.c reassembled remote...
CVE-2026-61858MEDIUM5.3ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to mis...
CVE-2026-61465MEDIUM6.5ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed op...
CVE-2026-60088MEDIUM6.8PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read f...
CVE-2026-56763MEDIUM6.3Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially crafted form field na...
CVE-2026-56296MEDIUM6.9Cap-go before 12.128.2 contains an information disclosure vulnerability in the public.transfer_app RPC function that ret...
CVE-2026-56240MEDIUM5.3Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows o...
CVE-2026-9017MEDIUM5.3The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all ve...
CVE-2026-6801MEDIUM5.3The Context Blog theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin...
CVE-2026-1382MEDIUM6.4The fresh Podcaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'freshpodcaster' shortcode...
CVE-2026-15010MEDIUM6.4The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6...
CVE-2026-12994MEDIUM5.3The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions u...
CVE-2026-12738MEDIUM4.3The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypas...
CVE-2026-12126MEDIUM6.4The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2026-12103MEDIUM4.3The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includi...
CVE-2026-11901MEDIUM5.3The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all version...
CVE-2026-11898MEDIUM4.4The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions...
CVE-2026-11591MEDIUM4.4The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a...
CVE-2026-10865MEDIUM5.3The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ...
CVE-2026-10041MEDIUM4.3The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in al...
CVE-2026-9738MEDIUM4.4The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conten...
CVE-2026-7620MEDIUM4.3The Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all versions up to, and incl...
CVE-2026-7559MEDIUM4.3The Affilia – Affiliate Program & Referral Tracking for WordPress plugin for WordPress is vulnerable to unauthorized acc...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now