2026 CVE Vulnerabilities

48,942 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-6447MEDIUM4.4The Call for Price for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings ...
CVE-2026-7604MEDIUM6.3A vulnerability was identified in JeecgBoot up to 3.9.1. This affects the function OpenApiController.add/OpenApiControll...
CVE-2026-7603MEDIUM6.3A vulnerability was determined in JeecgBoot up to 3.9.1. Affected by this issue is the function checkPathTraversalBatch ...
CVE-2026-6446MEDIUM5.4The My Social Feeds – Social Feeds Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all ...
CVE-2026-4658MEDIUM6.4The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored ...
CVE-2026-7638MEDIUM5.3The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Insecure Direct O...
CVE-2026-7602MEDIUM6.3A vulnerability was found in JeecgBoot up to 3.9.1. Affected by this vulnerability is an unknown functionality of the fi...
CVE-2026-7209MEDIUM6.4The Simple Link Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `qcopd-dire...
CVE-2026-6378MEDIUM6.4The Maxi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `/wp-json/maxi-blocks/v1.0/sty...
CVE-2026-7601MEDIUM5.3A vulnerability has been found in Open5GS up to 2.7.6. Affected is an unknown function of the file src/amf/gmm-handler.c...
CVE-2026-7600MEDIUM6.3A flaw has been found in ArtMin96 yii2-mcp-server 1.0.2. This impacts the function yii_command_help/yii_execute_command ...
CVE-2026-7599MEDIUM6.3A vulnerability was detected in Dayoooun hwpx-mcp 0.2.0. This affects the function save_document/export_to_text/export_t...
CVE-2026-7597MEDIUM6.3A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem...
CVE-2026-7596MEDIUM4.3A vulnerability has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this issue is the functi...
CVE-2026-7595MEDIUM6.3A flaw has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this vulnerability is the functio...
CVE-2026-42788MEDIUM6.9Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated memory exhau...
CVE-2026-39807MEDIUM6.3Reliance on Untrusted Inputs in a Security Decision vulnerability in mtrudel bandit allows unauthenticated transport-sta...
CVE-2026-39805MEDIUM6.3Inconsistent Interpretation of HTTP Requests vulnerability in mtrudel bandit allows HTTP request smuggling via duplicate...
CVE-2026-7591MEDIUM6.3A security flaw has been discovered in TimBroddin astro-mcp-server up to 1.1.1. The impacted element is an unknown funct...
CVE-2026-7589MEDIUM5.5A vulnerability was determined in ghantakiran splunk-mcp-integration up to 0b86b09d5e5adf0433acd43c975951224613a1a6. Imp...
CVE-2026-7588MEDIUM5.5A vulnerability was found in ggerve coding-standards-mcp. This issue affects the function get_style_guide/get_best_pract...
CVE-2026-35233MEDIUM4.4An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link f...
CVE-2026-26461MEDIUM6.5A Command Injection vulnerability in the web management interface in Aver PTC320UV2 0.1.0000.65 allows an unauthenticate...
CVE-2026-21996MEDIUM5.5An unprivileged attacker can reliably trigger a crash of the dtrace process with a malicious ELF binary due to an intege...
CVE-2026-7587MEDIUM4.3A vulnerability has been found in Open5GS up to 2.7.7. This vulnerability affects the function amf_nsmf_pdusession_handl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now