2026 CVE Vulnerabilities

44,049 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-56373MEDIUM5.3ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when me...
CVE-2026-56366MEDIUM6.5ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths...
CVE-2026-56354MEDIUM5.4n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirec...
CVE-2026-56329MEDIUM6.4Capgo before 12.128.2 contains a cross-tenant preview namespace collision vulnerability caused by non-bijective decoding...
CVE-2026-56312MEDIUM6.9Capgo before 12.128.2 contains an improper validation vulnerability in the accept_invitation endpoint that creates user ...
CVE-2026-56309MEDIUM5.4Capgo before 12.128.2 fails to enforce plan/quota restrictions on the /files/upload/attachments endpoint, allowing plan-...
CVE-2026-54470MEDIUM5.3Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Ref...
CVE-2026-56814MEDIUM6.9Plug.Parsers.MULTIPART, the multipart request-body parser used to handle file uploads and multipart forms, does not enfo...
CVE-2026-54468MEDIUM6.5Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. A low privileged ...
CVE-2026-14461MEDIUM5.1mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup() function. An attacker who can influence the TXT ...
CVE-2026-9857MEDIUM4.3The Invoice123 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.0. T...
CVE-2026-41877MEDIUM5.1R-SOFT DMS is vulnerable to Stored XSS in file upload functionality. Authenticated attacker can inject arbitrary HTML an...
CVE-2026-13710MEDIUM6.4The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vul...
CVE-2026-13247MEDIUM6.4The Logo Slider – Logo Carousel, Client Logo Slider & Brand Showcase for WordPress plugin for WordPress is vulnerable to...
CVE-2026-13010MEDIUM6.5The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL ...
CVE-2026-12918MEDIUM4.9The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to...
CVE-2026-11990MEDIUM5.3The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in al...
CVE-2026-9838MEDIUM6.1The ICS Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'htmltagtitle' parameter i...
CVE-2026-6802MEDIUM5.3The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, a...
CVE-2026-6440MEDIUM4.3The GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference plugin for WordPress is vulnerable to Cro...
CVE-2026-3907MEDIUM6.4The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wphostel-book' shortcode in all ve...
CVE-2026-1946MEDIUM4.3The GW AI Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab...
CVE-2026-15104MEDIUM6.5The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to g...
CVE-2026-15026MEDIUM4.3The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve...
CVE-2026-14475MEDIUM4.9The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now