2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-12071MEDIUM5.3The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied input, which is appended ...
CVE-2026-66493MEDIUM6.4Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths...
CVE-2026-66492MEDIUM6.1Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths...
CVE-2026-49008MEDIUM6.5By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to the integrity...
CVE-2026-18938MEDIUM6.2A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit a...
CVE-2026-49006MEDIUM5.3By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmiss...
CVE-2026-19079MEDIUM4.4A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. W...
CVE-2026-16027MEDIUM5.4Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Requ...
CVE-2026-15239MEDIUM5.3The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache...
CVE-2026-15211MEDIUM5.9The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal ...
CVE-2026-15148MEDIUM5.3The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates fro...
CVE-2026-12261MEDIUM5.3A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisonin...
CVE-2026-16265MEDIUM6.5The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not r...
CVE-2026-16039MEDIUM6.5The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, ...
CVE-2026-15386MEDIUM5.4The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an att...
CVE-2026-15359MEDIUM6.5The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allow...
CVE-2026-15245MEDIUM5.4The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript con...
CVE-2026-15214MEDIUM4.3The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription...
CVE-2026-15032MEDIUM6.1The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an...
CVE-2026-14331MEDIUM6.1The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a...
CVE-2026-12801MEDIUM6.4The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Range Slid...
CVE-2026-11907MEDIUM6.5The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This ...
CVE-2026-45204MEDIUM5.5Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger OOB access and kern...
CVE-2026-17264MEDIUM5.3Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of...
CVE-2026-7405MEDIUM5.5A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-B...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now