2026 CVE Vulnerabilities

48,297 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-8340MEDIUM4.3Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edit_file_contents perm...
CVE-2026-8997MEDIUM4.8vifm is vulnerable to a heap buffer overflow during the history merge process when saving the state file (vifminfo.json)...
CVE-2026-8672MEDIUM5.1Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Common or Default User...
CVE-2026-44618MEDIUM5.3Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users a...
CVE-2026-5755MEDIUM6.5Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.2, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to ...
CVE-2026-4646MEDIUM4.3Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate user-supp...
CVE-2026-4635MEDIUM5.3Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to archive the channe...
CVE-2026-3636MEDIUM4.3Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to sanitize team memb...
CVE-2026-25607MEDIUM5.7Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after analyzin...
CVE-2026-8692MEDIUM4.3The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPress is vulnerable to...
CVE-2026-8684MEDIUM5.3The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includ...
CVE-2026-8381MEDIUM5.4A broken access control vulnerability exists in the TeamViewer DEX Platform (On‑Premises) prior version 9.2. Certain bac...
CVE-2026-7798MEDIUM5.4The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin f...
CVE-2026-7636MEDIUM4.3The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is vulnerable to Sensitive Informat...
CVE-2026-7615MEDIUM4.3The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2026-5072MEDIUM6.5A bitwise shift vulnerability in Zephyr's PTP subsystem allows a remote attacker to cause undefined behavior and potenti...
CVE-2026-9104MEDIUM6.4The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Draft Post Title in all versions up...
CVE-2026-7509MEDIUM6.4The KIA Subtitle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `the-subtitle` short...
CVE-2026-7249MEDIUM4.3The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability c...
CVE-2026-6864MEDIUM6.1The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' param...
CVE-2026-4070MEDIUM4.3The Alfie – Feed Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2026-3481MEDIUM6.1The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode' parameter in al...
CVE-2026-2518MEDIUM4.3The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and activation due to missing ca...
CVE-2026-9053MEDIUM6.9Mothra would respect a default value given by a website for HTML file upload forms. An attacker could craft a website wi...
CVE-2026-46598MEDIUM5.3For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now