2026 CVE Vulnerabilities

48,334 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-44608MEDIUM5.9NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain...
CVE-2026-44390MEDIUM5.3NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets t...
CVE-2026-42923MEDIUM5.3NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator where the code path to...
CVE-2026-42534MEDIUM5.3NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purp...
CVE-2026-35070MEDIUM6.7Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization of Special Elements used...
CVE-2026-32792MEDIUM5.3NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNS...
CVE-2026-6405MEDIUM4.3The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) ...
CVE-2026-7385MEDIUM5.8The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email addresses and post au...
CVE-2026-6566MEDIUM4.3The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Insecure Direct ...
CVE-2026-5776MEDIUM6.1The Email Encoder WordPress plugin before 2.4.7 does not escape email addresses retrieved via user input, allowing unau...
CVE-2026-44392MEDIUM5.3Missing authorization vulnerability exists in Movable Type. Under certain conditions, when a user without administrator ...
CVE-2026-2955MEDIUM6.4The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '...
CVE-2026-9056MEDIUM5.4A stored cross-site scripting vulnerability has been found in the Talend Administration Center. An attacker with permiss...
CVE-2026-5075MEDIUM4.3The All in One SEO plugin for WordPress is vulnerable to Sensitive Information Exposure via 'internalOptions' localized ...
CVE-2026-8685MEDIUM6.5The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order' parameters in all ...
CVE-2026-8627MEDIUM6.1The Correct Prices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] var...
CVE-2026-8626MEDIUM6.1The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all version...
CVE-2026-8624MEDIUM6.1The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Param...
CVE-2026-8610MEDIUM4.3The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authorization bypass in all versions up to, and...
CVE-2026-8424MEDIUM4.3The Remove Yellow BGBOX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2026-8423MEDIUM4.3The JaviBola Custom Theme Test plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2026-8420MEDIUM6.1The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2026-8419MEDIUM4.3The Amazon Scraper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2026-8418MEDIUM4.3The Games Catalog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2...
CVE-2026-8038MEDIUM6.4The Faces of Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now