2026 CVE Vulnerabilities

65,007 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-78593MEDIUM4.3An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kiban...
CVE-2026-49455MEDIUM6.5Waku is the minimal React framework. Prior to version 1.0.0-beta.1, Waku's RSC request dispatcher invokes server actions...
CVE-2026-84968MEDIUM5.3An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who su...
CVE-2026-82024MEDIUM5.4LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site scripting vulnerability that allows authenticated ...
CVE-2026-82023MEDIUM4.3LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenti...
CVE-2026-85309MEDIUM5.3Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Acc...
CVE-2026-85308MEDIUM5.3Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrect...
CVE-2026-85307MEDIUM5.3Insertion of Sensitive Information Into Sent Data vulnerability in Kevin Pirnie KP Agent Ready allows Retrieve Embedded ...
CVE-2026-85306MEDIUM6.5Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting I...
CVE-2026-85305MEDIUM5.4Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery. This issue affects SEO...
CVE-2026-85304MEDIUM5.3Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templa...
CVE-2026-85303MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Bo...
CVE-2026-85302MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Th...
CVE-2026-85242MEDIUM6.9PlaywrightCapture contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval functionality. Wh...
CVE-2026-85186MEDIUM6.3A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is th...
CVE-2026-84849MEDIUM6.5Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions.
CVE-2026-84774MEDIUM6.1Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions.
CVE-2026-84769MEDIUM6.5Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions.
CVE-2026-84767MEDIUM5.3Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions.
CVE-2026-84766MEDIUM5.9Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.
CVE-2026-84762MEDIUM5.3Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.
CVE-2026-84758MEDIUM6.5Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions.
CVE-2026-84755MEDIUM6.5Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions.
CVE-2026-84754MEDIUM6.5Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions.
CVE-2026-84215MEDIUM6.5Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now