2026 CVE Vulnerabilities

43,273 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-17532MEDIUM6.1The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'seraph_accel_p...
CVE-2026-17505MEDIUM6.1The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v...
CVE-2026-15281MEDIUM6.5The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the w...
CVE-2026-11977MEDIUM6.5The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to ...
CVE-2026-11969MEDIUM4.9The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Paramete...
CVE-2026-11920MEDIUM4.9The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL ...
CVE-2026-11454MEDIUM6.5The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object...
CVE-2026-71201MEDIUM5In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assign...
CVE-2026-68080MEDIUM6.5It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated atta...
CVE-2026-68078MEDIUM6.5It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att...
CVE-2026-68077MEDIUM6.5An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to ...
CVE-2026-68075MEDIUM6.5An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service...
CVE-2026-67591MEDIUM6.5An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service...
CVE-2026-67555MEDIUM6.5It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att...
CVE-2026-67554MEDIUM6.5An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to ...
CVE-2026-67553MEDIUM6.5An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service...
CVE-2026-66277MEDIUM6.5It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att...
CVE-2026-66276MEDIUM6.5An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to ...
CVE-2026-66275MEDIUM6.5An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service...
CVE-2026-49004MEDIUM6.5The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabi...
CVE-2026-17515MEDIUM4.3The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisatio...
CVE-2026-16981MEDIUM5.3The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capa...
CVE-2026-16968MEDIUM6.5The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users...
CVE-2026-16942MEDIUM5.4The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page hand...
CVE-2026-16613MEDIUM4.3The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now