2026 CVE Vulnerabilities

44,067 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-60094MEDIUM6.9Vinchin Backup & Recovery through 9.0.0.86562 contains a heap buffer overflow vulnerability that allows unauthenticated ...
CVE-2026-15186MEDIUM6.3A vulnerability was identified in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /returnApply...
CVE-2026-12879MEDIUM5.9An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google...
CVE-2026-15182MEDIUM5.3A vulnerability has been found in GNU LibreDWG up to 0.13.4. The affected element is the function dwg_bmp of the file sr...
CVE-2026-9240MEDIUM4.3The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress is vulnerable to unauthorized modif...
CVE-2026-9237MEDIUM4.3The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization byp...
CVE-2026-9235MEDIUM4.3The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of ...
CVE-2026-9028MEDIUM5.3The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up ...
CVE-2026-9027MEDIUM5.3The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification...
CVE-2026-9021MEDIUM5.3The Easy Invoice plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.19. T...
CVE-2026-58307MEDIUM6.1Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Dat...
CVE-2026-58306MEDIUM6.1Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Es...
CVE-2026-58305MEDIUM6.1Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Point...
CVE-2026-58304MEDIUM6.1Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This iss...
CVE-2026-58303MEDIUM6.1Stack-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects E...
CVE-2026-56289MEDIUM5.5GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff...
CVE-2026-56288MEDIUM5.5GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Impro...
CVE-2026-4298MEDIUM4.3The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and includ...
CVE-2026-12590MEDIUM5.9Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an i...
CVE-2026-12428MEDIUM6.5The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ...
CVE-2026-5793MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Inrove Software an...
CVE-2026-56460MEDIUM6.5HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API respons...
CVE-2026-56459MEDIUM5.5HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure.  The application stores potentially s...
CVE-2026-1365MEDIUM6.5Insertion of sensitive information into sent data vulnerability in Sayax Energy Technologies Inc. OSOS allows Authentica...
CVE-2026-12433MEDIUM4.3The Hydra Booking – Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Obje...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now