2026 CVE Vulnerabilities

48,261 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-2237MEDIUM5.5A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager ...
CVE-2026-8942MEDIUM4.3The MetaMagic SEO Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2026-8906MEDIUM6.1The WP Promoter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2026-8042MEDIUM6.4The Github Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'repo' shortcode attribut...
CVE-2026-7618MEDIUM4.9The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to time-based blind SQL Injection vi...
CVE-2026-49001MEDIUM5.3Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cro...
CVE-2026-41704MEDIUM6.8AgentClient#handle_method (lines 264-303) processes every NATS reply. It calls inject_compile_log (line 273) on every re...
CVE-2026-41009MEDIUM5.8When the director sends a long-running request (e.g. compile_package), the agent's reply JSON is consumed by AgentClient...
CVE-2026-40826MEDIUM6.9A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dsgvo_contracts view...
CVE-2026-40822MEDIUM6.9A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset funct...
CVE-2026-40821MEDIUM6.9A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountByID funct...
CVE-2026-3897MEDIUM6.4The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `labb_a...
CVE-2026-3896MEDIUM6.4The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lsow_admin_aj...
CVE-2026-3895MEDIUM6.4The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `...
CVE-2026-3279MEDIUM6.5The Enable jQuery Migrate Helper plugin for WordPress is vulnerable to unauthorized modification of data due to a missin...
CVE-2026-3001MEDIUM6.1The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all version...
CVE-2026-2030MEDIUM6.4The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `...
CVE-2026-9014MEDIUM5.3The WP Promoter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec...
CVE-2026-8943MEDIUM4.3The GoStats for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2026-8941MEDIUM4.3The CDN Linker lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1...
CVE-2026-8939MEDIUM4.3The Search Simple Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi...
CVE-2026-8938MEDIUM4.3The auto making JSON-LD plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2026-8911MEDIUM6.1The WP AutoBuzz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2026-8903MEDIUM4.3The Two-factor authentication (formerly IP Vault) plugin for WordPress is vulnerable to Cross-Site Request Forgery in al...
CVE-2026-8899MEDIUM6.4The Auto Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'thumbnails' shortcode in a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now