2026 CVE Vulnerabilities

67,214 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-96456MEDIUM6.3The Reachy Mini Bluetooth service asks a connecting device for a PIN before it will accept commands. The check protects ...
CVE-2026-96455HIGH8.8The Reachy Mini daemon exposes an HTTP API for managing the robot. Its app installation endpoint, POST /apps/install in ...
CVE-2026-96442HIGH7.8A code execution flaw was found in Emacs, affecting versions prior to 31.2. The Flymake mode using language backends oth...
CVE-2026-90950MEDIUM5.3The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handle...
CVE-2026-87978MEDIUM5.3The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on one branch of its pay...
CVE-2026-87848LOW3.7The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have any authorisation or authentication on one of its A...
CVE-2026-87071MEDIUM5.3The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which metadata keys a form submission may supply...
CVE-2026-87070MEDIUM5.3The Forminator Forms WordPress plugin before 1.57.2.1 does not verify that a request came from a trusted proxy before pr...
CVE-2026-86612MEDIUM5.6The Ninja Tables WordPress plugin before 5.2.17 does not restrict shortcode expansion to administrator-authored table ro...
CVE-2026-86604MEDIUM4.8The GTranslate WordPress plugin before 5.0.1 does not remove shortcodes from the content of outgoing emails before expan...
CVE-2026-86601MEDIUM6.5The WP Recipe Maker WordPress plugin before 10.8.2 does not remove shortcodes from comment content before expanding it w...
CVE-2026-5696MEDIUM5.9Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability lies in the ‘group’ parameter of the ‘/admin/setti...
CVE-2026-5695HIGH8.4Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users ...
CVE-2026-96454HIGH8.2Pake turns a website into a desktop application built on Tauri. Every application it generates inherits two settings fro...
CVE-2026-96443MEDIUM6.5Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution...
CVE-2026-95627HIGH7.7When a Tauri application uses the dialog plugin's file or folder picker, an attacker with JavaScript execution (XSS) can...
CVE-2026-95626HIGH8.3Tauri's Content Security Policy hardening, which injects a random nonce to restrict script execution, provides zero prot...
CVE-2026-94251MEDIUM6.5A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resou...
CVE-2026-94243HIGH7.3A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue af...
CVE-2026-92001MEDIUM6.1Improper restriction of recursive entity references in DTDs ('XML entity expansion') vulnerability in Apache Sling XSS. ...
CVE-2026-91999MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. ...
CVE-2026-91928MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. ...
CVE-2026-91852MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. ...
CVE-2026-79616LOW0.6Out-of-bounds read while parsing untrusted SVG path strings in Qt Quick's Context2D.path / PathSvg.path.
CVE-2026-73192MEDIUM6.1An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when usin...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now