2026 CVE Vulnerabilities

45,294 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-12120MEDIUM5.3The FireBox Popups – Increase Sales and Grow Your Email List plugin for WordPress is vulnerable to Sensitive Information...
CVE-2026-12093MEDIUM5.3The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4...
CVE-2026-11784MEDIUM4.3The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vuln...
CVE-2026-11777MEDIUM4.9The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic...
CVE-2026-11776MEDIUM4.9The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic...
CVE-2026-11402MEDIUM6.4The Services Section Block – Showcase Service Details in Grid or Columns plugin for WordPress is vulnerable to Stored Cr...
CVE-2026-11360MEDIUM4.9The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_dire...
CVE-2026-11358MEDIUM4.4The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulne...
CVE-2026-11357MEDIUM4.3The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Sensitive Informati...
CVE-2026-10736MEDIUM4.9The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the...
CVE-2026-10623MEDIUM4.3The PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin plugin for WordPress is vulnerable to Insecur...
CVE-2026-10029MEDIUM5.3The Event Koi Lite – Events Calendar, Event Management, RSVP, and Tickets plugin for WordPress is vulnerable to Sensitiv...
CVE-2026-10023MEDIUM4.3The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPr...
CVE-2026-54533MEDIUM6.9vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, malicious algorithms ...
CVE-2026-54445MEDIUM6.9vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial us...
CVE-2026-50267MEDIUM4.7Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-50202MEDIUM5.9Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-50201MEDIUM6.5Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-44646MEDIUM5.3LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below,...
CVE-2026-44645MEDIUM6.5LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below,...
CVE-2026-44644MEDIUM6.1LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. Versions 10.25.7 and below are...
CVE-2026-12568MEDIUM6.5The postman_download module uses the workspace name field from the Postman API to construct the local directory path wit...
CVE-2026-12565MEDIUM5.3The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, re...
CVE-2026-8049MEDIUM5.3In SignalRGB versions prior to 1.3.7.0, the \\.\SignalIo device object is created without an explicit SDDL security desc...
CVE-2026-54386MEDIUM6.1marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenti...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now