2026 CVE Vulnerabilities

48,244 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-45841MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix divide-by-zero in OSF...
CVE-2026-45840MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: openvswitch: cap upcall PID array size and pre-size...
CVE-2026-45838MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: fix end-of-list detection in cgroup_storage_ge...
CVE-2026-42751MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking ...
CVE-2026-42750MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nexcess WPComplete...
CVE-2026-42744MEDIUM6.5Improper Validation of Specified Quantity in Input vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded...
CVE-2026-42732MEDIUM6.5Improper Validation of Specified Quantity in Input vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded...
CVE-2026-42726MEDIUM6.5Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Explo...
CVE-2026-42725MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in WP Wham Checkout Files Upload for WooCommerce checkout...
CVE-2026-3349MEDIUM6.1The MinhNhut Link Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter o...
CVE-2026-3348MEDIUM4.4The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings (D...
CVE-2026-3012MEDIUM6.8A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabl...
CVE-2026-2288MEDIUM4.8The myLinksDump plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_title' parameter in all ...
CVE-2026-2280MEDIUM4.8The rexCrawler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t...
CVE-2026-48968MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slid...
CVE-2026-48877MEDIUM6.5Insertion of Sensitive Information Into Sent Data vulnerability in Tom GenerateBlocks allows Retrieve Embedded Sensitive...
CVE-2026-2237MEDIUM5.5A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager ...
CVE-2026-8942MEDIUM4.3The MetaMagic SEO Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2026-8906MEDIUM6.1The WP Promoter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2026-8042MEDIUM6.4The Github Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'repo' shortcode attribut...
CVE-2026-7618MEDIUM4.9The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to time-based blind SQL Injection vi...
CVE-2026-49001MEDIUM5.3Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cro...
CVE-2026-41704MEDIUM6.8AgentClient#handle_method (lines 264-303) processes every NATS reply. It calls inject_compile_log (line 273) on every re...
CVE-2026-41009MEDIUM5.8When the director sends a long-running request (e.g. compile_package), the agent's reply JSON is consumed by AgentClient...
CVE-2026-40826MEDIUM6.9A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dsgvo_contracts view...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now