2026 CVE Vulnerabilities

65,056 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5502MEDIUM5.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course content m...
CVE-2026-5427MEDIUM5.3The Kubio plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 2.7.2. This is due...
CVE-2026-5234MEDIUM5.3The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includin...
CVE-2026-4853MEDIUM4.9The JetBackup – Backup, Restore & Migrate plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary Dire...
CVE-2026-3330MEDIUM4.9The Form Maker by 10Web plugin for WordPress is vulnerable to SQL Injection via the 'ip_search', 'startdate', 'enddate',...
CVE-2026-5052HIGH8.6Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This ...
CVE-2026-4666MEDIUM6.5The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($arg...
CVE-2026-4525HIGH8.8If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used t...
CVE-2026-3605HIGH8.1An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they w...
CVE-2026-5231HIGH7.2The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in al...
CVE-2026-5162MEDIUM6.4The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed ...
CVE-2026-4817MEDIUM6.5The MasterStudy LMS WordPress Plugin for Online Courses and Education plugin for WordPress is vulnerable to Time-based B...
CVE-2026-3488MEDIUM6.5The WP Statistics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14.1...
CVE-2026-40922MEDIUM5.4SiYuan is an open-source personal knowledge management system. In versions 3.6.1 through 3.6.3, a prior fix for XSS in b...
CVE-2026-40265MEDIUM5.9Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset download endpoint at /api/n...
CVE-2026-40263LOW3.7Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the login endpoint performs bcrypt pa...
CVE-2026-40262HIGH8.7Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset delivery handler serves upl...
CVE-2026-40260MEDIUM5.3pypdf is a free and open-source pure-python PDF library. In versions prior to 6.10.0, manipulated XMP metadata entity de...
CVE-2026-22734HIGH8.6Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UA...
CVE-2026-40322CRITICAL9SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendere...
CVE-2026-40318HIGH8.5SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttr...
CVE-2026-40259HIGH8.1SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, the /api/av/removeUnusedAttr...
CVE-2026-40255MEDIUM6.1AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In @adonisjs/http-server version...
CVE-2026-40253MEDIUM6.1openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. In versions 3.26.0 and below, the BER/DER deco...
CVE-2026-41113HIGH8.1sagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in notlshosts_auto in qmail-remot...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now