2026 CVE Vulnerabilities

64,997 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-85586MEDIUM6.9phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission ...
CVE-2026-85583MEDIUM6.5SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-read endpoint that fo...
CVE-2026-85582MEDIUM6.5SiYuan versions before v3.8.2 contain an unbounded session creation vulnerability in the publish-service Basic Auth hand...
CVE-2026-85580MEDIUM6.5SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-se...
CVE-2026-85579MEDIUM4.3SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-acces...
CVE-2026-85578MEDIUM6.5SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows reader...
CVE-2026-85577MEDIUM5.4AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php that allows una...
CVE-2026-19043MEDIUM4.3Missing Authorization vulnerability in Menulux Software Inc. Menulux Portal allows Accessing Functionality Not Properly ...
CVE-2026-18957MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Menulux Software I...
CVE-2026-85534MEDIUM5.9A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library ca...
CVE-2026-84045MEDIUM5.3The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip di...
CVE-2026-27347MEDIUM5.3Missing Authorization vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Secur...
CVE-2026-85547MEDIUM6.2A cross-site request forgery (CSRF) vulnerability exists in MISP due to form-security and CSRF protections being disable...
CVE-2026-85541MEDIUM5.4DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability. Authenticated remote attackers can...
CVE-2026-84044MEDIUM5.3The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 does not verify that a PayPal payment notification ...
CVE-2026-84043MEDIUM5.3The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of pa...
CVE-2026-81666MEDIUM6.5An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check fo...
CVE-2026-27086MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xtemos WoodMart al...
CVE-2026-13148MEDIUM6.3Missing release of memory after effective lifetime vulnerability in Softing smartLink allows resource leak exposure. Th...
CVE-2026-85528MEDIUM5.3Improper input validation of the auto-configuration account identifier in Snowflake JDBC Driver versions 4.2.0 through 4...
CVE-2026-85311MEDIUM5.3Missing Authorization vulnerability in Kings Plugins MarketKing allows Exploiting Incorrectly Configured Access Control ...
CVE-2026-32480MEDIUM5.3Missing Authorization vulnerability in WC Lovers WCFM Membership allows Exploiting Incorrectly Configured Access Control...
CVE-2026-27432MEDIUM5.4Authorization Bypass Through User-Controlled Key vulnerability in sc Internet Vivoo WP Rentals allows Exploiting Incorre...
CVE-2026-15937MEDIUM5.3Improper certificate validation in Checkmk <2.5.0p10 allows a relay and a push agent that share the same UUID to reuse e...
CVE-2026-85229MEDIUM6.1** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of input during web page generation ('cross-site scripting') vul...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now