2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-32469MEDIUM5.3Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.
CVE-2026-28180MEDIUM5.3Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.
CVE-2026-28179MEDIUM5.9Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.
CVE-2026-28178MEDIUM6.5Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.
CVE-2026-28169MEDIUM5.3Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.
CVE-2026-28146MEDIUM6.5Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 vers...
CVE-2026-25403MEDIUM6.5Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
CVE-2026-19045MEDIUM5.3A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog...
CVE-2026-19044MEDIUM5.3A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of...
CVE-2026-15246MEDIUM4.3The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, no...
CVE-2026-19041MEDIUM6.3A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the function this.packageSe...
CVE-2026-19040MEDIUM6.3A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown function of the file src/...
CVE-2026-18501MEDIUM6.4The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre...
CVE-2026-16316MEDIUM4.3OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame...
CVE-2026-70556MEDIUM5.1Hubzilla 11.2.1 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint handled by Zotlabs...
CVE-2026-19039MEDIUM5.3A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted ...
CVE-2026-19038MEDIUM6.3A security vulnerability has been detected in MonomythDevelopment la-forge-mcp 1.0.0. This issue affects the function sc...
CVE-2026-19037MEDIUM4.3A weakness has been identified in WonderTrader up to 0.9.9. This vulnerability affects the function MatchEngine::update_...
CVE-2026-0673MEDIUM5.3The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to...
CVE-2026-8166MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Indu...
CVE-2026-5391MEDIUM6.4The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute ...
CVE-2026-5158MEDIUM6.4The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored C...
CVE-2026-11983MEDIUM5.3The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up...
CVE-2026-55980MEDIUM5.5A denial-of-service vulnerability in CatchPulse could allow an attacker to conduct a stack buffer overrun attack, leadin...
CVE-2026-55979MEDIUM5.2An improper access control check in CatchPulse's named pipe communication interface could allow an attacker to invoke Ca...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now