2026 CVE Vulnerabilities

50,000 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-6048MEDIUM6.4The Flipbox Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flipbox widget...
CVE-2026-4801MEDIUM6.4The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via exter...
CVE-2026-40490MEDIUM6.8The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT...
CVE-2026-1838MEDIUM6.1The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode_id' parameter in all ...
CVE-2026-1559MEDIUM6.4The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in al...
CVE-2026-40593MEDIUM4.8ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the User Editor (UserEditor.php) rende...
CVE-2026-40485MEDIUM5.3ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the public API login endpoint (/api/pu...
CVE-2026-40483MEDIUM5.4ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the Pledge Editor renders donation com...
CVE-2026-40347MEDIUM5.3Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerabi...
CVE-2026-40346MEDIUM6.5NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t...
CVE-2026-40340MEDIUM6.1libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read vulner...
CVE-2026-40339MEDIUM5.2libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `pt...
CVE-2026-40338MEDIUM5.2libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in the...
CVE-2026-40337MEDIUM5.1The Sentry kernel is a high security level micro-kernel implementation made for high security embedded systems. A given ...
CVE-2026-40335MEDIUM5.2libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `pt...
CVE-2026-40333MEDIUM6.1libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, two functions in camlibs/ptp2...
CVE-2026-40486MEDIUM4.3Kimai is an open-source time tracking application. In versions 2.52.0 and below, the User Preferences API endpoint (PATC...
CVE-2026-40479MEDIUM5.4Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in Ki...
CVE-2026-2434MEDIUM6.4The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attribute...
CVE-2026-40353MEDIUM5.4wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the attribution_link property in Abs...
CVE-2026-40306MEDIUM6.5DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new in...
CVE-2026-40305MEDIUM4.3DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting i...
CVE-2026-40304MEDIUM5.3zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the unaccess handler (c...
CVE-2026-40302MEDIUM6.1zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template en...
CVE-2026-40301MEDIUM4.7DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now