2026 CVE Vulnerabilities

48,876 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-6672MEDIUM6.4The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via s...
CVE-2026-6344MEDIUM4.9The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This i...
CVE-2026-35254MEDIUM6.1Vulnerability in the Oracle OCI CLI product of Oracle Open Source Projects. The supported versions that is affected is 3...
CVE-2026-35253MEDIUM4.7Vulnerability in the Oracle Macoron Tool product of Oracle Open Source Projects. The supported versions that is affected...
CVE-2026-23927MEDIUM5.1A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead ...
CVE-2026-2306MEDIUM4.3The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation du...
CVE-2026-5753MEDIUM6.5The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions ...
CVE-2026-3208MEDIUM5.3The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a mis...
CVE-2026-7572MEDIUM5.5An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor befor...
CVE-2026-40934MEDIUM6.8Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign auth...
CVE-2026-41950MEDIUM6.5Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the fu...
CVE-2026-39402MEDIUM6.5lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_l...
CVE-2026-35527MEDIUM5Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues ...
CVE-2026-38947MEDIUM6.1FluentCMS 1.2.3 is vulnerable to Cross Site Scripting (XSS) in TextHTML plugin.
CVE-2026-35453MEDIUM5.4PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.3 and earlier, 2.0.0 through 2.1...
CVE-2026-34527MEDIUM5.3Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, SbieIniSe...
CVE-2026-33420MEDIUM5.3Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_det...
CVE-2026-32699MEDIUM5.3FacturaScripts is an open source accounting and invoicing software. In versions 2025.92 and earlier, the application fai...
CVE-2026-32603MEDIUM6.5Sandboxie is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a local denial...
CVE-2026-31893MEDIUM5.5Tunnelblick is an open source graphic user interface for OpenVPN on macOS. In versions 3.3beta26 through 9.0beta01, any ...
CVE-2026-31835MEDIUM5.4Vaultwarden is a Bitwarden-compatible server written in Rust. In versions 1.35.4 and earlier, the WebAuthn authenticatio...
CVE-2026-43002MEDIUM5.3An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session stor...
CVE-2026-38432MEDIUM6.1ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with ...
CVE-2026-7844MEDIUM6.3A vulnerability was detected in chatchat-space Langchain-Chatchat up to 0.3.1.3. This vulnerability affects the function...
CVE-2026-6907MEDIUM5.3An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erron...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now