2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-21822MEDIUM6.3HCLSoftware AppScan 360° was affected by a Path Traversal vulnerability in the ASReportService component. Improper handl...
CVE-2026-13635MEDIUM5.3An improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation Manager (DSM) before 7.2.1-...
CVE-2026-13623MEDIUM4.8An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in Sy...
CVE-2026-93493MEDIUM5.9A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by prov...
CVE-2026-92622MEDIUM6.4The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lightbox_class' Shortcode...
CVE-2026-92554MEDIUM6.1The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Reflecte...
CVE-2026-92249MEDIUM6.1The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter i...
CVE-2026-90981MEDIUM6.1The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting...
CVE-2026-85652MEDIUM6.5The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injectio...
CVE-2026-75961MEDIUM4.9The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the ...
CVE-2026-17607MEDIUM6.5The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the ...
CVE-2026-17586MEDIUM6.4The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vkExUnit_cta_img...
CVE-2026-16777MEDIUM4.9The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to...
CVE-2026-15004MEDIUM5.4The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2026-14472MEDIUM6.4The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kubio/copyright Block Co...
CVE-2026-13471MEDIUM4.3The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direc...
CVE-2026-12739MEDIUM4.3The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypas...
CVE-2026-11757MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics Tec...
CVE-2026-92714MEDIUM6.5The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and inclu...
CVE-2026-92561MEDIUM6.1The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in...
CVE-2026-91707MEDIUM5.3The The Divi theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5....
CVE-2026-90977MEDIUM5.3The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is e...
CVE-2026-90976MEDIUM5.3The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled before creating an acco...
CVE-2026-89330MEDIUM6.1The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for ...
CVE-2026-89278MEDIUM5.3The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is v...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now