2026 CVE Vulnerabilities

44,964 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-9180MEDIUM5.3The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key...
CVE-2026-8892MEDIUM6.4The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2026-8489MEDIUM6.4The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2026-12557MEDIUM5.3The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inc...
CVE-2026-11397MEDIUM5.5The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and in...
CVE-2026-12960MEDIUM6An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application o...
CVE-2026-12920MEDIUM4.9The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via ...
CVE-2026-12734MEDIUM6.4The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stor...
CVE-2026-12731MEDIUM6.4The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stor...
CVE-2026-12729MEDIUM4.3The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Miss...
CVE-2026-55726MEDIUM6.9The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious us...
CVE-2026-54477MEDIUM5.4The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks.
CVE-2026-13728MEDIUM4.4In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved...
CVE-2026-13377MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2026-13376MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2026-13375MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2026-13374MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2026-13373MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2026-13371MEDIUM4.9An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending ma...
CVE-2026-50722MEDIUM5.9Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding o...
CVE-2026-50721MEDIUM5.9Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authen...
CVE-2026-52188MEDIUM6.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2026-59102MEDIUM5.4Forgejo before 15.0.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execut...
CVE-2026-59101MEDIUM6.9AutoBangumi before 3.2.8 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated remote ...
CVE-2026-59100MEDIUM5LobeChat through 2.2.9 contains a broken object level authorization vulnerability that allows authenticated attackers to...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now