2026 CVE Vulnerabilities

46,946 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-34033MEDIUM5.4Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issu...
CVE-2026-34031MEDIUM6.5Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: throu...
CVE-2026-33582MEDIUM6.5Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: throu...
CVE-2026-28262MEDIUM6Dell iDRAC Tools, versions prior to 11.4.1.0, contains an Improper Link Resolution Before File Access ('Link Following')...
CVE-2026-25699MEDIUM6.1Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Ap...
CVE-2026-25688MEDIUM6.1Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: throu...
CVE-2026-41985MEDIUM5.1UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect ser...
CVE-2026-41984MEDIUM5.2UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect ser...
CVE-2026-41983MEDIUM4.3Null pointer dereference vulnerability in the browser module. Impact: Successful exploitation of this vulnerability may ...
CVE-2026-41982MEDIUM6.4Race condition vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availab...
CVE-2026-41981MEDIUM5.3Out-of-bounds write vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect av...
CVE-2026-41977MEDIUM5DoS vulnerability in the log service. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-41976MEDIUM6.6Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vulnerability may affec...
CVE-2026-41973MEDIUM5.9Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability...
CVE-2026-41972MEDIUM5.4Path traversal vulnerability in the SMS app. Impact: Successful exploitation of this vulnerability may affect availabili...
CVE-2026-4986MEDIUM5.3The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before ...
CVE-2026-41539MEDIUM6.1A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remot...
CVE-2026-8977MEDIUM6.4The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_ac...
CVE-2026-8940MEDIUM4.3The WP Meta Sort Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2026-8910MEDIUM6.1The WP Emoticon Rating plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2026-8909MEDIUM4.3The WpMobi plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.3....
CVE-2026-8907MEDIUM6.1The WP-Ultimate-Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1...
CVE-2026-8904MEDIUM4.3The FastPicker, an order picker and order management system (oms) for WooCommerce on steroids plugin for WordPress is vu...
CVE-2026-8902MEDIUM4.3The AJAX Report Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2026-8895MEDIUM6.4The kk blog card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blog-card' shortcod...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now