2026 CVE Vulnerabilities

45,269 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-56009MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricksable for Bri...
CVE-2026-56007MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Prod...
CVE-2026-54221MEDIUM5.1UBB.threads is vulnerable to Reflected XSS. The application improperly handles user input in certain requests, enabling ...
CVE-2026-54219MEDIUM5.1UBB.threads is vulnerable to Stored XSS via user posts and user profile fields. The application fails to properly saniti...
CVE-2026-44942MEDIUM6.5A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series...
CVE-2026-42490MEDIUM6.5[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-42489MEDIUM5.3[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-12539MEDIUM5.7Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-appl...
CVE-2026-12527MEDIUM6A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V3...
CVE-2026-12039MEDIUM5.7Docker Sandboxes (sbx) enforces an HTTP/S-only egress allowlist but does not apply it to DNS resolution: the per-network...
CVE-2026-8039MEDIUM6.4The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' shortcode attr...
CVE-2026-50643MEDIUM5.18cc is vulnerable to an Out‑of‑Bounds Read due to improper handling of #line directives and GNU linemarkers. The compile...
CVE-2026-2021MEDIUM6.4The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alwaysauto' shortc...
CVE-2026-9815MEDIUM6.5The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenti...
CVE-2026-55745MEDIUM5.4Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage ...
CVE-2026-28573MEDIUM5.5In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could l...
CVE-2026-12137MEDIUM6.1The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is...
CVE-2026-12136MEDIUM6.4The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysb...
CVE-2026-12111MEDIUM4.3The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to,...
CVE-2026-12098MEDIUM6.4The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed...
CVE-2026-9199MEDIUM4.3The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerabl...
CVE-2026-12120MEDIUM5.3The FireBox Popups – Increase Sales and Grow Your Email List plugin for WordPress is vulnerable to Sensitive Information...
CVE-2026-12093MEDIUM5.3The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4...
CVE-2026-11784MEDIUM4.3The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vuln...
CVE-2026-11777MEDIUM4.9The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now