2026 CVE Vulnerabilities

45,440 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-12301MEDIUM5.3Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
CVE-2026-12300MEDIUM5.3Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
CVE-2026-12299MEDIUM5.4JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, F...
CVE-2026-12298MEDIUM5.4Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152...
CVE-2026-8484MEDIUM4.8A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper due to a lack of size verification for th...
CVE-2026-10828MEDIUM6.9A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPor...
CVE-2026-54197MEDIUM6.5Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions.
CVE-2026-54190MEDIUM6.5Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.
CVE-2026-52714MEDIUM5.9Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= 12.4.16 versions.
CVE-2026-40809MEDIUM6.5Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Contro...
CVE-2026-2381MEDIUM6.5The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a ...
CVE-2026-10093MEDIUM6.4The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2026-9187MEDIUM5.3The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up t...
CVE-2026-5149MEDIUM6.5The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 Thi...
CVE-2026-50255MEDIUM6.7Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulne...
CVE-2026-10780MEDIUM4.3The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu...
CVE-2026-10635MEDIUM6.3On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core/ptables.c) maintain...
CVE-2026-6964MEDIUM5.3The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i...
CVE-2026-42014MEDIUM6.6A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can ...
CVE-2026-1766MEDIUM6.1A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracke...
CVE-2026-1765MEDIUM5.6A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This ...
CVE-2026-1764MEDIUM5.6A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially craf...
CVE-2026-12162MEDIUM5.5Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an ...
CVE-2026-48157MEDIUM6.1Slim is a PHP micro framework that enables users to write simple web applications and APIs. In versions 4.4.0 through 4....
CVE-2026-49775MEDIUM6.5Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now