2026 CVE Vulnerabilities

67,214 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-84026MEDIUM5.3The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not restric...
CVE-2026-83555MEDIUM5.3The Email Subscribers & Newsletters WordPress plugin before 5.9.35 does not verify the per-subscriber management token ...
CVE-2026-82843CRITICAL9The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity ass...
CVE-2026-81339MEDIUM4.3The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform a per-object ownership check when ...
CVE-2026-81338MEDIUM4.6The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not properly sanitise and restrict HTML in use...
CVE-2026-80342MEDIUM6.5The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.27 does not verify that a PayPal order supplied i...
CVE-2026-77766MEDIUM4.3The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not scope o...
CVE-2026-77765MEDIUM5.3The Better Payment WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the...
CVE-2026-75799CRITICAL9The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly...
CVE-2026-19438HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Mint Workbench I. T...
CVE-2026-18365MEDIUM4.3The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on one of its AJAX actions, al...
CVE-2026-18364MEDIUM4.3The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on several of its AJAX actions...
CVE-2026-16264MEDIUM6.5The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management ...
CVE-2026-14321HIGH8.2The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it uses for rate limit...
CVE-2026-96258MEDIUM4.3A vulnerability has been found in onSite internet GmbH Auktion NG Auktionssoftware up to 20260722. This affects an unkno...
CVE-2026-96257CRITICAL10A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element of...
CVE-2026-95958LOW3.3A security flaw has been discovered in JusticeRage Manalyze 1.0.0. Impacted is the function PE::_parse_relocations of th...
CVE-2026-95957MEDIUM4.3A vulnerability was found in SourceCodester Smart Attendance System with QR Code Scanner 1.0. This issue affects the fun...
CVE-2026-95930MEDIUM6.3A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6. Affected by this vulnerability is the fu...
CVE-2026-95929MEDIUM6.3A weakness has been identified in iFlytek astron-agent up to 1.0.7. Affected is an unknown function of the file console/...
CVE-2026-91777HIGH7.5Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of th...
CVE-2026-91776HIGH7.5TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, a...
CVE-2026-89425HIGH7.5UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error me...
CVE-2026-95928MEDIUM5.5A security flaw has been discovered in recommenders-team recommenders up to 1.2.1. This impacts the function pickle.load...
CVE-2026-95927HIGH7.3A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now