2026 CVE Vulnerabilities

64,618 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-27398MEDIUM5.3Missing Authorization vulnerability in WP Chill RSVP and Event Management allows Exploiting Incorrectly Configured Acces...
CVE-2026-27357MEDIUM5.3Missing Authorization vulnerability in Cornel Raiu WP Search Analytics allows Exploiting Incorrectly Configured Access C...
CVE-2026-27346MEDIUM4.9Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Sec...
CVE-2026-24592MEDIUM5.3Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Acce...
CVE-2026-24586MEDIUM5.4Missing Authorization vulnerability in Themeansar Newses allows Exploiting Incorrectly Configured Access Control Securit...
CVE-2026-24582MEDIUM4.3Missing Authorization vulnerability in WPPOOL FlexTable allows Exploiting Incorrectly Configured Access Control Security...
CVE-2026-24554MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Convers Lab WPSubscription allows Cross Site Request Forgery. This i...
CVE-2026-24527MEDIUM4.3Missing Authorization vulnerability in Patterns in the cloud Autoship Cloud for WooCommerce Subscription Products allows...
CVE-2026-9503LOW3.3A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file sr...
CVE-2026-9502MEDIUM5.3A vulnerability was identified in GNU LibreDWG up to 0.14. This affects the function decompress_R2004_section of the fil...
CVE-2026-9501LOW3.3A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function decompress_R2004_section...
CVE-2026-9500MEDIUM5.3A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section ...
CVE-2026-48852LOW3.7PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.
CVE-2026-48851LOW3.1PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not c...
CVE-2026-48850MEDIUM5.9PuTTY 0.72 before 0.84 has a double free in RSA KEX.
CVE-2026-48589MEDIUM5.4Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In ...
CVE-2026-44598MEDIUM5.4With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vu...
CVE-2026-43828MEDIUM6.5Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue...
CVE-2026-43827MEDIUM6.5Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 ...
CVE-2026-24597MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart allows Cross Site Request Forgery. This ...
CVE-2026-24574MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Static HTML/CSS allows Cross Site Request Fo...
CVE-2026-24545MEDIUM4.3Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Contro...
CVE-2026-9498MEDIUM6.3A vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass ...
CVE-2026-9497MEDIUM6.3A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject ...
CVE-2026-9486MEDIUM4.3A security flaw has been discovered in SourceCodester Student Grades Management System 1.0. This affects an unknown part...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now