2026 CVE Vulnerabilities

64,729 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6391MEDIUM6.1The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2026-6072MEDIUM6.5The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorization Bypass Through Us...
CVE-2026-5293MEDIUM6.4The 診断ジェネレータ作成プラグイン (Diagnosis Generator) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'js'...
CVE-2026-45232LOW3.7Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connect...
CVE-2026-43620MEDIUM5.5Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver...
CVE-2026-43619HIGH7.2Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod,...
CVE-2026-43618HIGH8.1Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit s...
CVE-2026-43617MEDIUM6.3Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access ...
CVE-2026-3985HIGH7.5The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection v...
CVE-2026-45585MEDIUM6.8Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". ...
CVE-2026-39309MEDIUM5.5Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas...
CVE-2026-35593MEDIUM6.8Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowled...
CVE-2026-34970MEDIUM5.3Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow a bugnote author to acces...
CVE-2026-34754MEDIUM4.3Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow an authenticated user to ...
CVE-2026-8495CRITICAL9.8Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing. This issue affects Date iCal: from 0....
CVE-2026-8493MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox In...
CVE-2026-8492LOW2.7Modification of Assumed-Immutable Data (MAID) vulnerability in Drupal Translate Drupal with GTranslate allows Resource L...
CVE-2026-8491LOW3.7Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View Permissions allows Forceful Brows...
CVE-2026-6871MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Obfuscate a...
CVE-2026-6367MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core...
CVE-2026-6366MEDIUM6.6Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow...
CVE-2026-6365MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core...
CVE-2026-6095MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Orejime all...
CVE-2026-34744MEDIUM5.3Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior permit a user to list and downl...
CVE-2026-34600MEDIUM5.7Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.5.2...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now