2026 CVE Vulnerabilities

43,273 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-16583MEDIUM6.1The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8...
CVE-2026-8790MEDIUM6.1The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST paramete...
CVE-2026-7753MEDIUM6.5The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing...
CVE-2026-71192MEDIUM6In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-C...
CVE-2026-71191MEDIUM6In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the Si...
CVE-2026-66344MEDIUM6.7NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerabi...
CVE-2026-5062MEDIUM4.9The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPre...
CVE-2026-18903MEDIUM4.3A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects so...
CVE-2026-15941MEDIUM6.5The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches f...
CVE-2026-11421MEDIUM6.5The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Inje...
CVE-2026-18896MEDIUM6.3A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown fun...
CVE-2026-18856MEDIUM4.7A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImporterAdminCheckXmlFil...
CVE-2026-45705MEDIUM5.3OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the fin...
CVE-2026-18853MEDIUM5.3A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the fu...
CVE-2026-18103MEDIUM4.9A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Program...
CVE-2026-18819MEDIUM4.3A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vul...
CVE-2026-18818MEDIUM6.3A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView o...
CVE-2026-70620MEDIUM6.8Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attacke...
CVE-2026-70594MEDIUM6.7Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions ...
CVE-2026-70593MEDIUM6.6Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff...
CVE-2026-70592MEDIUM5.5Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overw...
CVE-2026-70591MEDIUM4.1Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin ima...
CVE-2026-70590MEDIUM4.8Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed password...
CVE-2026-70589MEDIUM4.8Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to rede...
CVE-2026-52370MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now