2026 CVE Vulnerabilities

65,524 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-100869MEDIUM5.9Sylius versions before 2.1.16 and 2.2.9 fail to restrict payment request actions in the Shop API endpoint, allowing cust...
CVE-2026-100868MEDIUM6.3Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in si...
CVE-2026-100867LOW3.3spaceship-prompt through 4.22.5 fails to sanitize control characters from project manifest version fields before renderi...
CVE-2026-100866LOW3.3onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, ...
CVE-2026-97165MEDIUM5.3Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 - The “return” par...
CVE-2026-97164HIGH7Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in Event Gallery extensio...
CVE-2026-100749MEDIUM5.1Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event Gallery extension < 6.5.0 - Only orphaned fi...
CVE-2026-100748MEDIUM6.9Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0
CVE-2026-100747MEDIUM5.1Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF toke...
CVE-2026-94417LOW2.3When an application enables both OCSP and CRL revocation checking on one WOLFSSL_CTX or certificate manager, wolfSSL ski...
CVE-2026-93304MEDIUM6.3A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has...
CVE-2026-93302HIGH8.3MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any ...
CVE-2026-89136HIGH8.3When using RPK (Raw Public Key), the client side of a TLS 1.2, 1.3 and DTLS 1.2 connection could accept an unsolicited s...
CVE-2026-89135MEDIUM6.3A failed X509_verify_cert call permanently plants an unverified attacker CA in the shared CertManager, bypassing certifi...
CVE-2026-89134MEDIUM6.3A certificate with no dNSName SAN but another SAN type present (e.g. registeredID or iPAddress) bypassed the Subject CN ...
CVE-2026-89133MEDIUM6.3wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to properly e...
CVE-2026-89102HIGH8.3In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response s...
CVE-2026-15442LOW2.3In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS ...
CVE-2026-94419LOW2.3Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of th...
CVE-2026-94418LOW2.3Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from the parse t...
CVE-2026-100741CRITICAL9.8Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3...
CVE-2026-97319MEDIUM6.8The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribu...
CVE-2026-97227MEDIUM5.9The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership chec...
CVE-2026-96899MEDIUM6.8The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one o...
CVE-2026-96897MEDIUM5.3The Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on one of its AJAX actions...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now