2026 CVE Vulnerabilities

48,096 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-38931MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp ...
CVE-2026-38930MEDIUM6.5OpenRapid RapidCMS v1.3.1 was discovered to contain an authentication bypass in the /template/default/menu.php component...
CVE-2026-9674MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows atta...
CVE-2026-6957MEDIUM4.9Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to constr...
CVE-2026-49102MEDIUM6.1Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes compo...
CVE-2026-49059MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing. ...
CVE-2026-49053MEDIUM5.3Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured ...
CVE-2026-49052MEDIUM4.3Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured ...
CVE-2026-49051MEDIUM4.3Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured...
CVE-2026-49047MEDIUM4.3Missing Authorization vulnerability in DearHive DearFlip allows Exploiting Incorrectly Configured Access Control Securit...
CVE-2026-49045MEDIUM4.3Missing Authorization vulnerability in WP Media Adminimize allows Exploiting Incorrectly Configured Access Control Secur...
CVE-2026-49044MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Kruit Advan...
CVE-2026-48973MEDIUM4.3Missing Authorization vulnerability in Benbodhi SVG Support allows Exploiting Incorrectly Configured Access Control Secu...
CVE-2026-48927MEDIUM5.5Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting...
CVE-2026-48926MEDIUM4.3Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allow...
CVE-2026-48925MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration Plugin 0.7.3 and earlier allows attacker...
CVE-2026-48924MEDIUM4.3Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to pe...
CVE-2026-48923MEDIUM4.3Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation...
CVE-2026-48919MEDIUM6.6Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.
CVE-2026-48918MEDIUM6.6Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.
CVE-2026-48917MEDIUM6.6Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation.
CVE-2026-48916MEDIUM6.6Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals.
CVE-2026-48545MEDIUM6.8Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Spa...
CVE-2026-47119MEDIUM6.1Agent Zero before version 1.15 contains a stored cross-site scripting vulnerability that allows attackers to execute arb...
CVE-2026-45571MEDIUM5.4go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now