2026 CVE Vulnerabilities

64,997 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-80190MEDIUM6.1Apache Allura: stored XSS via SVN code repositories.  Git repositories are not known to be affected.  The vulnerability ...
CVE-2026-6217MEDIUM6.3Use of a One-Way hash without a salt vulnerability in Pik Online Software Solutions Inc. Pik Online Portal allows Crypta...
CVE-2026-84146MEDIUM5.3The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-statu...
CVE-2026-82194MEDIUM5.5The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before ...
CVE-2026-82193MEDIUM5.5The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name be...
CVE-2026-82186MEDIUM4.1The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly validate a pagination parameter before using it...
CVE-2026-81347MEDIUM5.9The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable director...
CVE-2026-80438MEDIUM5.9The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninj...
CVE-2026-80180MEDIUM6.1Stored XSS via markdown HTML processing in Apache Allura. This issue affects Apache Allura: from through 1.20.0. U...
CVE-2026-79632MEDIUM5.3The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in sub...
CVE-2026-79631MEDIUM5.3The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predictable locat...
CVE-2026-79630MEDIUM5.3The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout order bump i...
CVE-2026-74853MEDIUM6.8The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing ...
CVE-2026-71216MEDIUM5.3PagerDuty alarm hook transmits the integration routing key over cleartext HTTP. PagerDuty serves this endpoint over H...
CVE-2026-17517MEDIUM5.3The Content Views WordPress plugin before 4.5.1.2 does not check whether the user requesting a view is allowed to read ...
CVE-2026-85409MEDIUM6.3A vulnerability was identified in Eleveo Quality Management 9.7.0. The affected element is the function QuestionnaireSer...
CVE-2026-85408MEDIUM4.3A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-...
CVE-2026-85407MEDIUM4.3A vulnerability was found in Eleveo Quality Management 9.7.0. This issue affects some unknown processing of the file /en...
CVE-2026-85401MEDIUM6.3A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functional...
CVE-2026-85149MEDIUM5.3SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote...
CVE-2026-85383MEDIUM6.3A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the...
CVE-2026-85382MEDIUM4.3A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f6138...
CVE-2026-85381MEDIUM5.3A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a061...
CVE-2026-49509MEDIUM4.4Out-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers. This issue affects rLottie: 256...
CVE-2026-85456MEDIUM5.5MOOS-IvP through 24.8.1 fails to properly validate variable names extracted from alog files in the SplitHandler, allowin...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now