2026 CVE Vulnerabilities

45,220 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-12619MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip G...
CVE-2026-21768MEDIUM6.3The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to prope...
CVE-2026-9143MEDIUM5.3There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missing range checks in Co...
CVE-2026-49231MEDIUM5.4Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed identity headers to upst...
CVE-2026-47341MEDIUM6.5Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from certain configuration...
CVE-2026-44915MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default configuration of cas-au...
CVE-2026-44046MEDIUM5.8Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac plugin under defaul...
CVE-2026-12706MEDIUM6.5A use-after-free vulnerability was found in FFmpeg's RASC video decoder. The decode_move() function initializes a read p...
CVE-2026-11941MEDIUM5.6Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The “...
CVE-2026-8296MEDIUM5.6In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payloa...
CVE-2026-56138MEDIUM5.3AIL framework contains a path traversal vulnerability in the /objects/item/diff endpoint. The endpoint accepts item iden...
CVE-2026-6798MEDIUM5.3The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized access in all version...
CVE-2026-3640MEDIUM5.3The STRABL – A checkout solution plugin for WordPress is vulnerable to Missing Authentication in all versions up to and ...
CVE-2026-9822MEDIUM6.5The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of its AJAX handlers, a...
CVE-2026-9013MEDIUM4.3The Bogo plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9....
CVE-2026-8118MEDIUM6.5The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrary ...
CVE-2026-7547MEDIUM4.9The Woosa – Marktplaats for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in ...
CVE-2026-56132MEDIUM6.9In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array...
CVE-2026-56131MEDIUM4.9libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a...
CVE-2026-4328MEDIUM6.4The Advanced Import plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includi...
CVE-2026-1856MEDIUM6.4The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom booking fi...
CVE-2026-12644MEDIUM5.5Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of b...
CVE-2026-12430MEDIUM4.4The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio...
CVE-2026-12157MEDIUM6.4The BetterDocs - Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to S...
CVE-2026-11989MEDIUM6.5The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vuln...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now