2026 CVE Vulnerabilities

44,054 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-1946MEDIUM4.3The GW AI Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab...
CVE-2026-15104MEDIUM6.5The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to g...
CVE-2026-15026MEDIUM4.3The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve...
CVE-2026-14475MEDIUM4.9The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via ...
CVE-2026-12955MEDIUM4.3The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil...
CVE-2026-12924MEDIUM6.4The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to S...
CVE-2026-12400MEDIUM4.3The FlowForms – Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in al...
CVE-2026-12108MEDIUM4.4The Highlighting Code Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ...
CVE-2026-11992MEDIUM4.3The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3...
CVE-2026-40009MEDIUM6.5Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated users can escalate t...
CVE-2026-12276MEDIUM5.3The LA-Studio Element Kit for Elementor WordPress plugin before 1.6.1 does not check whether user registration is enable...
CVE-2026-12123MEDIUM6.4The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an...
CVE-2026-21057MEDIUM6.8Improper input validation in Samsung Pass prior to version 5.2.10.3 allows local privileged attackers to write out-of-bo...
CVE-2026-21056MEDIUM4.8Improper authorization in Samsung Health prior to version 7.00.0.107 allows local attackers to access connected device i...
CVE-2026-21054MEDIUM6.9Improper export of android application components in InputSharing prior to version 2.7.01.4 allows local attackers to ac...
CVE-2026-21053MEDIUM5.1Improper input validation in Samsung Email prior to version 6.2.13.1 allows local attackers to create arbitrary files wi...
CVE-2026-21052MEDIUM6.8Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files ...
CVE-2026-21051MEDIUM5.1Incorrect default permissions in WLAN security prior to SMR Jul-2026 Release 1 allows local attackers to configure Tence...
CVE-2026-21050MEDIUM5.1Improper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive inf...
CVE-2026-21044MEDIUM5.8Improper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 allows local attackers to bypass the persiste...
CVE-2026-21043MEDIUM6.7Path traversal in Wallpaper service prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files wi...
CVE-2026-21041MEDIUM6.9Improper access control in SamsungSEAgentService prior to SMR Jul-2026 Release 1 allows local attackers to access sensit...
CVE-2026-21040MEDIUM6.9Improper access control in IAFDService prior to SMR Jul-2026 Release 1 allows local privileged attackers to use the priv...
CVE-2026-21039MEDIUM6.9Improper access control in Settings prior to SMR Jul-2026 Release 1 allows local attackers to configure Theft protection...
CVE-2026-15332MEDIUM6.3A security flaw has been discovered in zhayujie CowAgent up to 2.1.0. The impacted element is an unknown function of the...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now