2026 CVE Vulnerabilities

45,261 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-56131MEDIUM4.9libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a...
CVE-2026-4328MEDIUM6.4The Advanced Import plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includi...
CVE-2026-1856MEDIUM6.4The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom booking fi...
CVE-2026-12644MEDIUM5.5Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of b...
CVE-2026-12430MEDIUM4.4The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio...
CVE-2026-12157MEDIUM6.4The BetterDocs - Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to S...
CVE-2026-11989MEDIUM6.5The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vuln...
CVE-2026-11752MEDIUM5.9A vulnerability has been identified in armeria-xds versions 1.38.0 through 1.39.0, where DataSourceStream in the xDS mod...
CVE-2026-10779MEDIUM4.3The Classified Listing – Classified ads & Business Directory plugin for WordPress is vulnerable to Missing Authorization...
CVE-2026-10720MEDIUM5.1Canonical MicroCeph versions from the squid and tentacle track are vulnerable to a path traversal issue in the remote-im...
CVE-2026-10034MEDIUM5.3The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin...
CVE-2026-11775MEDIUM4.3The User Admin Simplifier plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2026-12049MEDIUM6.1Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA validate and register endpoints honoured the user...
CVE-2026-12048MEDIUM5.4Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL ...
CVE-2026-12047MEDIUM5.4HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoi...
CVE-2026-56074MEDIUM6.8PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequ...
CVE-2026-49205MEDIUM6.5phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryC...
CVE-2026-22674MEDIUM4.8Hashgraph Guardian through 3.6.0, fixed in commit ba8c566, contains a stored cross-site scripting vulnerability that all...
CVE-2026-45696MEDIUM6.5OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in...
CVE-2026-56099MEDIUM5.3OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulnerability in the mpls_do_error function wi...
CVE-2026-48983MEDIUM5.8pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, a symlink...
CVE-2026-48982MEDIUM5.8pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, when upda...
CVE-2026-48981MEDIUM6.7pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, pam_usb c...
CVE-2026-48980MEDIUM6.3pam_usb provides hardware authentication for Linux using removable media. In versions prior to 0.9.2, getenv() environm...
CVE-2026-47847MEDIUM5.3Bitnami MariaDB Galera container images and Helm chart are affected by a hardcoded default credential vulnerability in t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now