2026 CVE Vulnerabilities

49,206 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-7268MEDIUM6.3A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This impacts the function save_category o...
CVE-2026-7267MEDIUM6.3A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects an unknown function of the file /view...
CVE-2026-7266MEDIUM6.3A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. The impacted element is the function save_o...
CVE-2026-7265MEDIUM6.3A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the f...
CVE-2026-7264MEDIUM6.3A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function get_cart_items o...
CVE-2026-41607MEDIUM6.5Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommen...
CVE-2026-41606MEDIUM5.3Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are reco...
CVE-2026-40980MEDIUM6.5In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when ha...
CVE-2026-40979MEDIUM6.1In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected version...
CVE-2026-7238MEDIUM4.7A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PH...
CVE-2026-7235MEDIUM5.5A security vulnerability has been detected in ErlichLiu claude-agent-sdk-master up to b185aa7ff0d864581257008077b4010fca...
CVE-2026-4911MEDIUM5.3The Booking Package plugin for WordPress is vulnerable to Price Manipulation in versions up to, and including, 1.7.06 Th...
CVE-2026-4805MEDIUM6.4The Woostify plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.0 T...
CVE-2026-41525MEDIUM6.5KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of th...
CVE-2026-40966MEDIUM5.9In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histo...
CVE-2026-7233MEDIUM6.1A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gid...
CVE-2026-7230MEDIUM4.3A vulnerability was found in SourceCodester Safety Anger Pad 1.0. The affected element is an unknown function. The manip...
CVE-2026-7229MEDIUM6.3A vulnerability was found in code-projects Coaching Management System 1.0. This affects an unknown function of the file ...
CVE-2026-5306MEDIUM5.4The Check & Log Email WordPress plugin before 2.0.13 does not properly handle email replacement, which could allow unau...
CVE-2026-6809MEDIUM6.4The Social Post Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Threads embed handler in...
CVE-2026-6725MEDIUM6.4The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' ...
CVE-2026-6551MEDIUM6.4The Timeline Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' a...
CVE-2026-7217MEDIUM5.5A security vulnerability has been detected in Deepractice PromptX up to 2.4.0. The affected element is the function read...
CVE-2026-0711MEDIUM6.8A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions ...
CVE-2026-7200MEDIUM4.3A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is some unknown ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now