2026 CVE Vulnerabilities

45,121 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-9183MEDIUM4.3The 24liveblog - live blog tool plugin for WordPress is vulnerable to Exposure of Sensitive Information in versions up t...
CVE-2026-9175MEDIUM5.3The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorizati...
CVE-2026-9172MEDIUM5.3The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modifi...
CVE-2026-8905MEDIUM6.1The Osiris Signature Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2026-8896MEDIUM6.4The MIR blocks and shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribut...
CVE-2026-8865MEDIUM6.4The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '...
CVE-2026-8690MEDIUM5.3The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions...
CVE-2026-8688MEDIUM4.3The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu...
CVE-2026-8628MEDIUM6.1The EntreDroppers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all ver...
CVE-2026-8622MEDIUM6.1The Image Sizes on Demand plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Server Varia...
CVE-2026-8617MEDIUM5.3The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, a...
CVE-2026-8614MEDIUM4.3The Assistio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check a...
CVE-2026-7617MEDIUM5.3The Secufor_OAuth plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.7....
CVE-2026-6292MEDIUM4.3The MP Customize Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up t...
CVE-2026-12094MEDIUM5.3The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a mi...
CVE-2026-11997MEDIUM4.3The Bulk SEO Image plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1....
CVE-2026-11370MEDIUM6.4The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ...
CVE-2026-10552MEDIUM4.3The Blue Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 2.0.1....
CVE-2026-10531MEDIUM5.4The AI Share & Summarize WordPress plugin before 2.0.4 does not sanitise and escape some of its shortcode attributes bef...
CVE-2026-9539MEDIUM6.5An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp...
CVE-2026-12488MEDIUM6.2A memory corruption vulnerability exists in the GV-Cloud functionality of GeoVision GV-VMS V20 20.0.2.  A specially cr...
CVE-2026-11614MEDIUM6.4The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '...
CVE-2026-6458MEDIUM5.1Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authenticat...
CVE-2026-48493MEDIUM5.5Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PA...
CVE-2026-47693MEDIUM6.9Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 are vulnerable ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now