2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-73192MEDIUM6.1An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when usin...
CVE-2026-95625MEDIUM5.9The Tauri updater plugin verifies update binaries using minisign signatures, but the signature covers only the raw binar...
CVE-2026-92378MEDIUM4.1A session management vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware uniFLOW Online. Und...
CVE-2026-91817MEDIUM6.1A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of wide strings in embedded P...
CVE-2026-91814MEDIUM5.3A signature validation vulnerability exists in Foxit PDF Editor/Reader’s handling of incrementally updated PDF documents...
CVE-2026-91810MEDIUM6.1A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF image masks....
CVE-2026-91808MEDIUM6.1A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor Reader’s handling of PDF image objects with inc...
CVE-2026-91807MEDIUM6.1A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed image soft-mask ...
CVE-2026-91796MEDIUM6.1The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows special...
CVE-2026-91788MEDIUM4.7When implementing the JavaScript interface, Foxit PDF Editor/Reader did not perform the attribute authorization checks r...
CVE-2026-50228MEDIUM6.1An unauthenticated local attacker can connect to the Electron DevTools endpoint exposed by Acer NitroSense software (ver...
CVE-2026-50227MEDIUM6.1An unauthenticated local attacker can connect to the MQTT broker over its localhost WebSocket endpoint in Acer NitroSens...
CVE-2026-6831MEDIUM6.5The Advanced Contact form 7 DB plugin for WordPress is vulnerable to missing authorization in all versions up to, and in...
CVE-2026-5924MEDIUM6.4The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps bloc...
CVE-2026-93511MEDIUM5.3The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature before processing payment...
CVE-2026-93510MEDIUM4.3The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not validate the claimed reward amount or res...
CVE-2026-91073MEDIUM6.8The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputti...
CVE-2026-91025MEDIUM4.3The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager W...
CVE-2026-91024MEDIUM6.8The Booking Manager WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iC...
CVE-2026-90985MEDIUM5.3The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 does not apply WordPress's post-password protection ...
CVE-2026-89331MEDIUM5.3The FluentBoards WordPress plugin before 2.1.0 does not properly restrict the member data returned by its public, token...
CVE-2026-88997MEDIUM6.8The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key before outputting it i...
CVE-2026-88929MEDIUM5.3The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a produc...
CVE-2026-87981MEDIUM4.7The Paymob for WooCommerce WordPress plugin before 4.1.14 does not perform a capability check on several admin AJAX acti...
CVE-2026-87979MEDIUM5.3The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on the card-token branch...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now