2026 CVE Vulnerabilities

44,805 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-6371MEDIUM4.8Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Limatek System Inc...
CVE-2026-14250MEDIUM6.3The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and inclu...
CVE-2026-12936MEDIUM4.9The Recurio – Ultimate Subscription for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the ...
CVE-2026-6280MEDIUM6.5Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consu...
CVE-2026-57259MEDIUM6.5The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, th...
CVE-2026-57258MEDIUM6.1The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underl...
CVE-2026-57257MEDIUM6.1During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-o...
CVE-2026-57255MEDIUM6.1The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malfo...
CVE-2026-57253MEDIUM6.1An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an in...
CVE-2026-57243MEDIUM6.1During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document stat...
CVE-2026-57241MEDIUM6.1The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related...
CVE-2026-9731MEDIUM4.3The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2026-14500MEDIUM5.3The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and i...
CVE-2026-12097MEDIUM5.3The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2...
CVE-2026-12041MEDIUM4.4The Chatra Live Chat + ChatBot + Cart Saver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin ...
CVE-2026-11798MEDIUM6.1The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Refle...
CVE-2026-10570MEDIUM6.4The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repea...
CVE-2026-60001MEDIUM6.5sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
CVE-2026-59998MEDIUM6.5sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if th...
CVE-2026-59997MEDIUM5.4internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important ...
CVE-2026-59996MEDIUM5.4scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs betwee...
CVE-2026-59995MEDIUM5.4sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is u...
CVE-2026-55438MEDIUM6.8Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7...
CVE-2026-55437MEDIUM5.4Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7...
CVE-2026-55433MEDIUM5.4Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now