2026 CVE Vulnerabilities

47,106 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-8883MEDIUM6.4The Global Body Mass Index Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gbmical...
CVE-2026-8882MEDIUM6.4The WP ApplicantStack Jobs Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attri...
CVE-2026-8880MEDIUM6.4The RomanCart Ecommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blclass' attribute (a...
CVE-2026-8841MEDIUM6.4The Extra Settings for RocketChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rocketchat'...
CVE-2026-8499MEDIUM5.3The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in ver...
CVE-2026-7662MEDIUM6.4The ePaperFlip Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'publicationid' attri...
CVE-2026-41980MEDIUM5.5Permission control vulnerability in the file preview module. Impact: Successful exploitation of this vulnerability may a...
CVE-2026-41979MEDIUM5.5Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect i...
CVE-2026-41978MEDIUM4.4Permission control vulnerability in the clone module. Impact: Successful exploitation of this vulnerability may affect s...
CVE-2026-41975MEDIUM6.3Permission management vulnerability in the network management module. Impact: Successful exploitation of this vulnerabil...
CVE-2026-41854MEDIUM6.5Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provid...
CVE-2026-41853MEDIUM5.3Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Fr...
CVE-2026-41852MEDIUM5.3A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocati...
CVE-2026-41847MEDIUM5.3Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions:...
CVE-2026-41846MEDIUM6.1Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP ...
CVE-2026-41845MEDIUM6.1Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the br...
CVE-2026-41844MEDIUM6.1A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly sp...
CVE-2026-41843MEDIUM5.9Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected ...
CVE-2026-41841MEDIUM5.9Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. A...
CVE-2026-41840MEDIUM5.9Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affect...
CVE-2026-41839MEDIUM4.2A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerab...
CVE-2026-41715MEDIUM6.1In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may ...
CVE-2026-41710MEDIUM5.9An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the applicati...
CVE-2026-11623MEDIUM4.5A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free of the file image.c. ...
CVE-2026-11603MEDIUM6.1The Product Filter Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'args[f...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now