2026 CVE Vulnerabilities

48,935 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-7643MEDIUM4.3A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This impacts an unknown function of the file Next.js of t...
CVE-2026-7642MEDIUM6.3A vulnerability was detected in pskill9 website-downloader up to 0.1.0. This affects the function download_website of th...
CVE-2026-7633MEDIUM6.5A vulnerability was identified in Totolink N300RH 6.1c.1353_B20190305. This impacts the function setUploadSetting of the...
CVE-2026-7631MEDIUM5.4A vulnerability was found in code-projects Online Hospital Management System 1.0. The impacted element is an unknown fun...
CVE-2026-7629MEDIUM6.3A flaw has been found in kleneway awesome-cursor-mpc-server up to 2.0.1. Impacted is the function runCodeReviewTool of t...
CVE-2026-3504MEDIUM5.3The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Infor...
CVE-2026-0703MEDIUM6.4The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
CVE-2026-7628MEDIUM6.3A vulnerability was detected in crazyrabbitLTC mcp-code-review-server up to 0.1.0. This issue affects the function execu...
CVE-2026-6817MEDIUM5.8The Quiz Maker by AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rate_reason' parameter ...
CVE-2026-6525MEDIUM5.5IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4
CVE-2026-4790MEDIUM5.4The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored C...
CVE-2026-7627MEDIUM6.3A security vulnerability has been detected in 8nite metatrader-4-mcp 1.0.0. This vulnerability affects the function Call...
CVE-2026-7612MEDIUM4.7A vulnerability was determined in itsourcecode Courier Management System 1.0. Affected is an unknown function of the fil...
CVE-2026-5077MEDIUM5.4The Total theme for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and includ...
CVE-2026-4024MEDIUM5.3The Royal Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ...
CVE-2026-6457MEDIUM6.5The Geo Mashup plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geo_mashup_null_fields' par...
CVE-2026-6449MEDIUM5.3The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization i...
CVE-2026-4650MEDIUM5.3The FundPress – WordPress Donation Plugin for WordPress is vulnerable to authorization bypass in versions up to and incl...
CVE-2026-7605MEDIUM6.3A security flaw has been discovered in JeecgBoot up to 3.9.1. This vulnerability affects the function CommonController.u...
CVE-2026-43058MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix pass-by-value structs causing MSA...
CVE-2026-6916MEDIUM6.4The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vul...
CVE-2026-6812MEDIUM4.4The Ona theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.26 via ...
CVE-2026-6447MEDIUM4.4The Call for Price for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings ...
CVE-2026-7604MEDIUM6.3A vulnerability was identified in JeecgBoot up to 3.9.1. This affects the function OpenApiController.add/OpenApiControll...
CVE-2026-7603MEDIUM6.3A vulnerability was determined in JeecgBoot up to 3.9.1. Affected by this issue is the function checkPathTraversalBatch ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now