2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-90990MEDIUM5.3Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 a...
CVE-2026-25262MEDIUM6.9Memory corruption while processing a crafted ELF file in the Primary Bootloader.
CVE-2026-15095MEDIUM4.9The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress is vu...
CVE-2026-9004MEDIUM4.3The WP-CRM System – Manage Clients and Projects plugin for WordPress is vulnerable to Sensitive Information Exposure in ...
CVE-2026-95503MEDIUM6.8A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution...
CVE-2026-91092MEDIUM4.3The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5....
CVE-2026-7622MEDIUM4.3The ThumbPress plugin for WordPress is vulnerable to unauthorized access in versions up to and including 6.2.1. This is ...
CVE-2026-74765MEDIUM6.5Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumula...
CVE-2026-4123MEDIUM4.3The RW Elephant Rental Inventory plugin for WordPress is vulnerable to Missing Authorization in all versions up to and i...
CVE-2026-1645MEDIUM4.4The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_currency' parameter and the...
CVE-2026-18439MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere...
CVE-2026-18345MEDIUM4.3The WP User Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2026-16778MEDIUM6.4The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
CVE-2026-12995MEDIUM4.3The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, ...
CVE-2026-93655MEDIUM6.1The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpbc_auto_fill' param...
CVE-2026-88788MEDIUM6.8The Text Styler WordPress plugin through 1.1.1 does not sanitise and escape user-supplied styling values before outputti...
CVE-2026-85653MEDIUM6.4The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'other_attributes' Bl...
CVE-2026-94492MEDIUM6.3A security vulnerability has been detected in Yonyou U8cloud 5.x. This vulnerability affects unknown code of the file /u...
CVE-2026-93711MEDIUM6.5Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array. The routi...
CVE-2026-93709MEDIUM5.3Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard...
CVE-2026-76974MEDIUM5.3SAP Fiori Launchpad does not sufficiently validate certain user-controlled input. An unauthenticated attacker could craf...
CVE-2026-94490MEDIUM4.7A security flaw has been discovered in OctoPrint 1.0.0. Affected by this issue is the function executeSystemCommand of t...
CVE-2026-94489MEDIUM4.3A vulnerability was identified in OctoPrint 1.0.0. Affected by this vulnerability is the function _validate of the file ...
CVE-2026-94625MEDIUM5.3vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests cr...
CVE-2026-94536MEDIUM4.3lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now