2026 CVE Vulnerabilities

45,376 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-49072MEDIUM6.5Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions.
CVE-2026-49071MEDIUM6.5Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions.
CVE-2026-48783MEDIUM4.8Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accept...
CVE-2026-48782MEDIUM6.8Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 t...
CVE-2026-47340MEDIUM6.5Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. ...
CVE-2026-47277MEDIUM6.5Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos fro...
CVE-2026-45436MEDIUM6.5Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions.
CVE-2026-44587MEDIUM6.1CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_typ...
CVE-2026-42357MEDIUM6.5Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do...
CVE-2026-41280MEDIUM4.9Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthoriz...
CVE-2026-40724MEDIUM6.5CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions.
CVE-2026-40723MEDIUM4.3Subscriber Broken Access Control in Bricks Builder <= 2.1.4 versions.
CVE-2026-40722MEDIUM5.5Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Contro...
CVE-2026-39595MEDIUM4.7Author Broken Access Control in W3 Total Cache <= 2.9.1 versions.
CVE-2026-39578MEDIUM5.5Unauthenticated PHP Object Injection in Valiance <= 1.2 versions.
CVE-2026-39577MEDIUM5.5Unauthenticated PHP Object Injection in Playroom <= 1.4.1 versions.
CVE-2026-39433MEDIUM6.5Subscriber Arbitrary Content Deletion in WPAMS < 49.5.3 versions.
CVE-2026-2604MEDIUM5.6A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpa...
CVE-2026-28587MEDIUM5.5In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing per...
CVE-2026-28576MEDIUM5.5In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to l...
CVE-2026-28575MEDIUM5.5In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession...
CVE-2026-27870MEDIUM4.8An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration actio...
CVE-2026-27869MEDIUM6.9An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration ac...
CVE-2026-27868MEDIUM6.9An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration ac...
CVE-2026-27410MEDIUM6.5Unauthenticated Deserialization of untrusted data in Slimstat Analytics < 5.4.0 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now