2026 CVE Vulnerabilities

44,976 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-53333MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/mincore: handle non-swap entries before !CONFIG_...
CVE-2026-53332MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: slimbus: qcom-ngd-ctrl: Register callbacks after cr...
CVE-2026-53331MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl-...
CVE-2026-53328MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sched_ext: Don't warn on NULL cgrp_moving_from in s...
CVE-2026-53327MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: debugobjects: Do not fill_pool() if pi_blocked_on ...
CVE-2026-53326MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: debugobjects: Don't call fill_pool() in early boot ...
CVE-2026-53909MEDIUM6.5MCO does not correctly validate types of uploaded files. File upload validation functionality relies only on client-side...
CVE-2026-53908MEDIUM4.3MCO is vulnerable to User Enumeration through authentication-related functionalities. The application returns distinguis...
CVE-2026-53907MEDIUM5.4MCO is vulnerable to Stored Cross‑Site Scripting (XSS) via the application logo upload functionality. An attacker with t...
CVE-2026-53902MEDIUM6.5MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership...
CVE-2026-14258MEDIUM6.5A flaw was found in dhcpcd's IPv6 Neighbor Discovery Router Advertisement processing. A specially crafted IPv6 Router Ad...
CVE-2026-10095MEDIUM6.4The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtext' parameter in...
CVE-2026-27435MEDIUM5.3Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Securit...
CVE-2026-13454MEDIUM6.5The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in a...
CVE-2026-12754MEDIUM6.1The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '...
CVE-2026-56016MEDIUM5.9CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. The gene...
CVE-2026-13733MEDIUM6.4The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attri...
CVE-2026-12732MEDIUM6.4The LearnPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_wrapper_form' shortcode ...
CVE-2026-12435MEDIUM4.3The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to authorization bypass in a...
CVE-2026-12408MEDIUM4.3The Slim SEO – A Fast & Automated SEO Plugin For WordPress plugin for WordPress is vulnerable to Unauthorized Private Co...
CVE-2026-10540MEDIUM5.6The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offl...
CVE-2026-10096MEDIUM4.3The Qi Blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includin...
CVE-2026-11887MEDIUM4.3The Salon Booking System WordPress plugin before 10.30.20 does not have proper authorisation checks on one of its AJAX ...
CVE-2026-11570MEDIUM4.2The User Submitted Posts WordPress plugin before 20260608 does not escape a submitted value before outputting it in an ...
CVE-2026-11562MEDIUM4.3The WS Form LITE WordPress plugin before 1.11.8 does not have a capability check on one of its settings-update actions,...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now