2026 CVE Vulnerabilities

49,581 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-19070MEDIUM6.3A vulnerability was detected in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the fil...
CVE-2026-19069MEDIUM6.3A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This affects an unknown funct...
CVE-2026-19068MEDIUM6.3A weakness has been identified in itsourcecode Hospital Management System 1.0. The impacted element is an unknown functi...
CVE-2026-19067MEDIUM6.3A security flaw has been discovered in itsourcecode Hospital Management System 1.0. The affected element is an unknown f...
CVE-2026-19066MEDIUM5.3A vulnerability was identified in SourceCodester Online Examination & Learning Management System 1.0. Impacted is an unk...
CVE-2026-19065MEDIUM6.3A vulnerability was determined in SourceCodester Online Examination & Learning Management System 1.0. This issue affects...
CVE-2026-19064MEDIUM5.3A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affe...
CVE-2026-19062HIGH7.3A vulnerability has been found in chiuwingyan house up to dea6bcceaebe2b364a5a209747f48ecc2b2dc670. This affects an unkn...
CVE-2026-19061MEDIUM6.3A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndD...
CVE-2026-19060MEDIUM5.3A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This impacts an unknown function. Such manipulat...
CVE-2026-19059LOW3.3A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. This affects the function read of the file metag...
CVE-2026-19058MEDIUM5.3A vulnerability was found in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function DataInterpreter ...
CVE-2026-19054MEDIUM5.3A vulnerability was detected in Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. This issue affec...
CVE-2026-18487MEDIUM5.4A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name s...
CVE-2026-18367CRITICAL9.3A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS ...
CVE-2026-17032CRITICAL9.8Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allo...
CVE-2026-16620HIGH7.5The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist f...
CVE-2026-16619HIGH7.5The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attem...
CVE-2026-16067MEDIUM5.3The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the ...
CVE-2026-15734CRITICAL9.8A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated att...
CVE-2026-15733CRITICAL9.8A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injectio...
CVE-2026-15732CRITICAL9.8A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functiona...
CVE-2026-15256MEDIUM4.8The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate ...
CVE-2026-15208MEDIUM5.3The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, p...
CVE-2026-15152MEDIUM5.3The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now