2026 CVE Vulnerabilities

64,772 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-92410MEDIUM4.3The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up del...
CVE-2026-87840MEDIUM5.3The Tripzzy WordPress plugin before 1.5.1 does not perform any capability or ownership checks on its administrative boo...
CVE-2026-87068MEDIUM6.6The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a r...
CVE-2026-84223MEDIUM6.8The Kirki WordPress plugin before 6.3.1 does not sanitize uploaded SVG files while making them uploadable site-wide, al...
CVE-2026-81653MEDIUM4.2The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an imag...
CVE-2026-16542MEDIUM4.1The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before req...
CVE-2026-14844MEDIUM6.8The Master Slider WordPress plugin through 3.11.2 does not sanitise and escape some of its shortcode attributes before ...
CVE-2026-93965MEDIUM6.6A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected is the function subprocess.Popen of the file backend/aiops...
CVE-2026-93964MEDIUM5.3A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCe...
CVE-2026-93963MEDIUM6.3A security vulnerability has been detected in itsourcecode Leave Management System 1.0. This affects an unknown function...
CVE-2026-93961MEDIUM5.3A security flaw has been discovered in Dromara UJCMS up to 12.3.1. The affected element is the function usernameExist of...
CVE-2026-93960MEDIUM4.3A vulnerability was identified in Pixelfed up to 0.12.11. Impacted is the function instancePeers of the file app/Http/Co...
CVE-2026-86552MEDIUM5.4SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acqui...
CVE-2026-93957MEDIUM4.3A vulnerability has been found in olivier-ls PHP-FTS up to 1.1.3. This affects the function SearchEngine::matchesSingleF...
CVE-2026-94057MEDIUM5.3Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead dep...
CVE-2026-94055MEDIUM5.3Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.
CVE-2026-94054MEDIUM5.3Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.
CVE-2026-93988MEDIUM6.5QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows a...
CVE-2026-93955MEDIUM4.3A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is the functio...
CVE-2026-93954MEDIUM4.3A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSet...
CVE-2026-82672MEDIUM6.3Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allow...
CVE-2026-94001MEDIUM6.5A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint...
CVE-2026-94000MEDIUM6.6A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue oc...
CVE-2026-93999MEDIUM4.2A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution...
CVE-2026-93984MEDIUM5.3OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptograph...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now