2026 CVE Vulnerabilities

43,031 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-47231HIGH8.1Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-c...
CVE-2026-47230MEDIUM6.5Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` mode `file_re...
CVE-2026-47229MEDIUM5.4Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/sso/clients.php` validates an `adm...
CVE-2026-47228MEDIUM5.2Admidio is an open-source user management solution. `modules/registration.php` mode `send_login` regenerates a random pa...
CVE-2026-47227MEDIUM6.5Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (...
CVE-2026-16999MEDIUM6.3Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows S...
CVE-2026-71408MEDIUM5.3A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7....
CVE-2026-71407MEDIUM5.6A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an...
CVE-2026-70468HIGH8.1A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7....
CVE-2026-70467LOW3.8A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM...
CVE-2026-70466MEDIUM5.3A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7....
CVE-2026-57858HIGH8.9Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagMa...
CVE-2026-53996HIGH7.3NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unpr...
CVE-2026-47226MEDIUM6.5Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload...
CVE-2026-26035CRITICAL9.8An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6....
CVE-2026-70560MEDIUM5.4Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-pri...
CVE-2026-70465HIGH8.1A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7....
CVE-2026-18044LOW3.7The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later use...
CVE-2026-17008MEDIUM5.3The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status i...
CVE-2026-16990MEDIUM5.3The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-si...
CVE-2026-16747MEDIUM6.5The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes...
CVE-2026-16621MEDIUM5.3The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succee...
CVE-2026-15213MEDIUM5.3The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-...
CVE-2026-15045MEDIUM6.5The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against...
CVE-2026-11325HIGH8.8Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now