2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-19066MEDIUM5.3A vulnerability was identified in SourceCodester Online Examination & Learning Management System 1.0. Impacted is an unk...
CVE-2026-19065MEDIUM6.3A vulnerability was determined in SourceCodester Online Examination & Learning Management System 1.0. This issue affects...
CVE-2026-19064MEDIUM5.3A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affe...
CVE-2026-19061MEDIUM6.3A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndD...
CVE-2026-19060MEDIUM5.3A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This impacts an unknown function. Such manipulat...
CVE-2026-19058MEDIUM5.3A vulnerability was found in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function DataInterpreter ...
CVE-2026-19054MEDIUM5.3A vulnerability was detected in Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. This issue affec...
CVE-2026-18487MEDIUM5.4A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name s...
CVE-2026-16067MEDIUM5.3The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the ...
CVE-2026-15256MEDIUM4.8The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate ...
CVE-2026-15208MEDIUM5.3The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, p...
CVE-2026-15152MEDIUM5.3The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment ...
CVE-2026-15149MEDIUM5.3The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total ar...
CVE-2026-15147MEDIUM5.3The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming paymen...
CVE-2026-14936MEDIUM5.3The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the s...
CVE-2026-14842MEDIUM5.3The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record b...
CVE-2026-14831MEDIUM5.3The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured minimum booking durat...
CVE-2026-14306MEDIUM4.3The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected co...
CVE-2026-13342MEDIUM5.3The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-base...
CVE-2026-12901MEDIUM5.9The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, ...
CVE-2026-12501MEDIUM5.3The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent...
CVE-2026-11361MEDIUM5.9The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payme...
CVE-2026-68747MEDIUM6.1Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in the ...
CVE-2026-66843MEDIUM6.1Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex ...
CVE-2026-66829MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allow...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now