2026 CVE Vulnerabilities

65,368 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-100749MEDIUM5.1Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event Gallery extension < 6.5.0 - Only orphaned fi...
CVE-2026-100748MEDIUM6.9Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0
CVE-2026-100747MEDIUM5.1Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF toke...
CVE-2026-94417LOW2.3When an application enables both OCSP and CRL revocation checking on one WOLFSSL_CTX or certificate manager, wolfSSL ski...
CVE-2026-93304MEDIUM6.3A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has...
CVE-2026-93302HIGH8.3MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any ...
CVE-2026-89136HIGH8.3When using RPK (Raw Public Key), the client side of a TLS 1.2, 1.3 and DTLS 1.2 connection could accept an unsolicited s...
CVE-2026-89135MEDIUM6.3A failed X509_verify_cert call permanently plants an unverified attacker CA in the shared CertManager, bypassing certifi...
CVE-2026-89134MEDIUM6.3A certificate with no dNSName SAN but another SAN type present (e.g. registeredID or iPAddress) bypassed the Subject CN ...
CVE-2026-89133MEDIUM6.3wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to properly e...
CVE-2026-89102HIGH8.3In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response s...
CVE-2026-15442LOW2.3In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS ...
CVE-2026-94419LOW2.3Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of th...
CVE-2026-94418LOW2.3Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from the parse t...
CVE-2026-100741CRITICAL9.8Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3...
CVE-2026-97319MEDIUM6.8The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribu...
CVE-2026-97227MEDIUM5.9The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership chec...
CVE-2026-96899MEDIUM6.8The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one o...
CVE-2026-96897MEDIUM5.3The Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on one of its AJAX actions...
CVE-2026-96896HIGH7.2The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation c...
CVE-2026-96895MEDIUM6.8The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before output...
CVE-2026-92995MEDIUM5.3The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handle...
CVE-2026-92436MEDIUM5.3The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loa...
CVE-2026-89006MEDIUM6.8The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it ...
CVE-2026-89003MEDIUM4.1The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now