2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-89093MEDIUM5.3The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Info...
CVE-2026-89081MEDIUM6.1The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin...
CVE-2026-88944MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to authorization bypass in all v...
CVE-2026-15760MEDIUM6.5The Divi Essential plugin for WordPress is vulnerable to sensitive information exposure in versions up to, and including...
CVE-2026-15660MEDIUM4.3The SEO Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.4.7. Thi...
CVE-2026-12042MEDIUM4.4The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v...
CVE-2026-77820MEDIUM6.4The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'empty' Shortcode Attribute in all ...
CVE-2026-93921MEDIUM4.3SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only ...
CVE-2026-77875MEDIUM6.8The application protects access through its calculator-style vault passcode, but the stored data is not bound to that au...
CVE-2026-93574MEDIUM6.5A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending ...
CVE-2026-93562MEDIUM6.5A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote...
CVE-2026-85272MEDIUM4.3Open edX Platform enables the authoring and delivery of online learning at any scale. From Aspen.1 until Ulmo and Verawo...
CVE-2026-85271MEDIUM6.1Open edX Platform enables the authoring and delivery of online learning at any scale. From Redwood until Ulmo and Verawo...
CVE-2026-71855MEDIUM5.9Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2026-63448MEDIUM5.9Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2026-61670MEDIUM6.5microsandbox is an easy, fast, local-first microVM runtime and library. Prior to 0.5.10, sdk/rust/lib/runtime/spawn.rs s...
CVE-2026-57229MEDIUM5.3Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr...
CVE-2026-93873MEDIUM4.3Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to...
CVE-2026-93871MEDIUM5.4Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticate...
CVE-2026-93870MEDIUM4.3Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge...
CVE-2026-93869MEDIUM6.1Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect de...
CVE-2026-93838MEDIUM5.9SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails t...
CVE-2026-91205MEDIUM6A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation ...
CVE-2026-91203MEDIUM6A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a syml...
CVE-2026-91202MEDIUM6.1A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory co...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now