2026 CVE Vulnerabilities

43,274 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-16297MEDIUM4.1The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-impor...
CVE-2026-16289MEDIUM4.3The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending me...
CVE-2026-16057MEDIUM6.5The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its...
CVE-2026-15931MEDIUM6.1The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthent...
CVE-2026-15383MEDIUM6.1The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, whic...
CVE-2026-15260MEDIUM4.3The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in...
CVE-2026-15254MEDIUM6.5The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrat...
CVE-2026-13340MEDIUM6.1The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz ext...
CVE-2026-6695MEDIUM5.5A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (...
CVE-2026-6694MEDIUM5.5A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable...
CVE-2026-18585MEDIUM5.3A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 a...
CVE-2026-18584MEDIUM5.4A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impact...
CVE-2026-18583MEDIUM5.5A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAcc...
CVE-2026-13586MEDIUM5.3In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also a...
CVE-2026-58063MEDIUM5.3In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue al...
CVE-2026-20498MEDIUM6In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local es...
CVE-2026-20497MEDIUM6In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation...
CVE-2026-20496MEDIUM4.4In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information...
CVE-2026-20494MEDIUM5.5In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disc...
CVE-2026-20493MEDIUM4.4In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of servi...
CVE-2026-20492MEDIUM5.5In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial ...
CVE-2026-20491MEDIUM5.5In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of ser...
CVE-2026-20490MEDIUM4.4In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of servic...
CVE-2026-20489MEDIUM4.4In display, there is a possible information disclosure due to an integer overflow. This could lead to local information ...
CVE-2026-20488MEDIUM4.4In display, there is a possible information disclosure due to a missing bounds check. This could lead to local informati...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now