2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-19356MEDIUM5.3A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/dat...
CVE-2026-19354MEDIUM6.3A vulnerability was found in lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc873a9d8b09. The impacted element is an u...
CVE-2026-19353MEDIUM5A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the fi...
CVE-2026-19350MEDIUM6.3A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/in...
CVE-2026-19347MEDIUM6.3A vulnerability was identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processin...
CVE-2026-19345MEDIUM6.5A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/Up...
CVE-2026-19340MEDIUM6.3A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file bac...
CVE-2026-19339MEDIUM6.3A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is th...
CVE-2026-19338MEDIUM5.3A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processG...
CVE-2026-19337MEDIUM5.3A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/...
CVE-2026-19336MEDIUM5.3A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.crea...
CVE-2026-19335MEDIUM5.3A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function ...
CVE-2026-18603MEDIUM6.5The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ...
CVE-2026-18465MEDIUM6.5The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is a...
CVE-2026-18037MEDIUM6.5The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of it...
CVE-2026-17014MEDIUM5.3The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its ...
CVE-2026-16992MEDIUM6.5The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of it...
CVE-2026-16965MEDIUM4.3The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, a...
CVE-2026-16032MEDIUM6.1The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated an...
CVE-2026-19334MEDIUM5.3A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. This affects an unknown pa...
CVE-2026-19333MEDIUM5.3A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a...
CVE-2026-19332MEDIUM5.3A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functi...
CVE-2026-19331MEDIUM5.3A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0.0. This affects the function readCanvas/writeCanva...
CVE-2026-19330MEDIUM5.3A vulnerability was determined in angrysky56 advanced-reasoning-mcp 1.0.0. The impacted element is the function create_s...
CVE-2026-19329MEDIUM5.3A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390. The affected element i...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now