2026 CVE Vulnerabilities

44,969 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-12472MEDIUM5.3The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypa...
CVE-2026-12134MEDIUM4.3The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to authorization b...
CVE-2026-12122MEDIUM5.3The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Sensitive Informat...
CVE-2026-11896MEDIUM5.3The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all...
CVE-2026-10104MEDIUM4.4The Product Video Gallery for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom_t...
CVE-2026-5348MEDIUM5.3The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Di...
CVE-2026-13704MEDIUM6.4The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2026-13357MEDIUM4.9The Houzez Property Feed plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions...
CVE-2026-11965MEDIUM6.5The User Registration & Membership WordPress plugin before 5.2.0 does not enforce payment completion before activating ...
CVE-2026-11600MEDIUM4.3The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to unauthorized access o...
CVE-2026-11592MEDIUM4.3The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for W...
CVE-2026-10089MEDIUM6.4The Insert Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post custom field keys (meta key ...
CVE-2026-10077MEDIUM6.8The yootheme WordPress theme before 5.0.35 does not prevent its bundled front-end framework from treating certain HTML a...
CVE-2026-55792MEDIUM6Craft CMS is a content management system (CMS). In versions starting from 4.0.0-RC1 and prior to 4.18.0, and 5.0.0-RC1 a...
CVE-2026-55791MEDIUM6.9Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, ...
CVE-2026-50280MEDIUM6Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 and above prior to 5.9.21, the EntriesController::...
CVE-2026-50283MEDIUM5.3Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 through 5.9.20, and 4.0.0-RC1 through 4.17.13 contain...
CVE-2026-14421MEDIUM6.5Uninitialized Use in Dawn in Google Chrome on ChromeOS prior to 150.0.7871.46 allowed a remote attacker to obtain potent...
CVE-2026-14418MEDIUM4.3Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data v...
CVE-2026-14414MEDIUM5.3Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who...
CVE-2026-14410MEDIUM4.3Inappropriate implementation in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromis...
CVE-2026-14408MEDIUM6.5Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensit...
CVE-2026-14406MEDIUM5.9Out of bounds read in V8 in Google Chrome prior to 150.0.7871.46 allowed an attacker who convinced a user to install a m...
CVE-2026-14404MEDIUM6.5Inappropriate implementation in PDFium in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI s...
CVE-2026-14402MEDIUM6.5Uninitialized Use in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to obtain potent...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now