2026 CVE Vulnerabilities

48,018 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-10057MEDIUM4.8ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privi...
CVE-2026-10052MEDIUM4.1A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can...
CVE-2026-10039MEDIUM4.9The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter i...
CVE-2026-9243MEDIUM6.4The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direct...
CVE-2026-49322MEDIUM4.3Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year al...
CVE-2026-9714MEDIUM6.4The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of th...
CVE-2026-6324MEDIUM4.8A flaw was found in libsoup. A remote attacker could exploit an unsigned to signed conversion error in the `soup_body_in...
CVE-2026-6275MEDIUM6.4The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in vers...
CVE-2026-2128MEDIUM5.3The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versi...
CVE-2026-8995MEDIUM4.3The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Sensitive Information ...
CVE-2026-7430MEDIUM4.4The Post Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including...
CVE-2026-6892MEDIUM5.1Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with...
CVE-2026-6891MEDIUM5.1Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a l...
CVE-2026-9996MEDIUM6.5Out of bounds read in WebRTC in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to obtain potenti...
CVE-2026-9989MEDIUM6.3Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to bypass same ...
CVE-2026-9986MEDIUM4.2Insufficient validation of untrusted input in OptimizationGuide in Google Chrome prior to 148.0.7778.216 allowed a remot...
CVE-2026-9985MEDIUM5.3Insufficient validation of untrusted input in Media in Google Chrome on ChromeOS prior to 148.0.7778.216 allowed a remot...
CVE-2026-9981MEDIUM6.5Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potent...
CVE-2026-9980MEDIUM5Insufficient validation of untrusted input in Printing in Google Chrome prior to 148.0.7778.216 allowed a remote attacke...
CVE-2026-9979MEDIUM5Insufficient validation of untrusted input in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker w...
CVE-2026-9971MEDIUM5.4Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convin...
CVE-2026-9955MEDIUM4.3Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker to leak cr...
CVE-2026-9953MEDIUM6.5Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sen...
CVE-2026-9943MEDIUM4.3Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-...
CVE-2026-9942MEDIUM5Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the re...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now