2026 CVE Vulnerabilities

50,042 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-6080MEDIUM6.5The Tutor LMS plugin for WordPress is vulnerable to SQL Injection in versions up to and including 3.9.8. This is due to ...
CVE-2026-5502MEDIUM5.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course content m...
CVE-2026-5427MEDIUM5.3The Kubio plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 2.7.2. This is due...
CVE-2026-5234MEDIUM5.3The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includin...
CVE-2026-4853MEDIUM4.9The JetBackup – Backup, Restore & Migrate plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary Dire...
CVE-2026-3330MEDIUM4.9The Form Maker by 10Web plugin for WordPress is vulnerable to SQL Injection via the 'ip_search', 'startdate', 'enddate',...
CVE-2026-4666MEDIUM6.5The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($arg...
CVE-2026-5162MEDIUM6.4The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed ...
CVE-2026-4817MEDIUM6.5The MasterStudy LMS WordPress Plugin for Online Courses and Education plugin for WordPress is vulnerable to Time-based B...
CVE-2026-3488MEDIUM6.5The WP Statistics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14.1...
CVE-2026-40922MEDIUM5.4SiYuan is an open-source personal knowledge management system. In versions 3.6.1 through 3.6.3, a prior fix for XSS in b...
CVE-2026-40265MEDIUM5.9Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset download endpoint at /api/n...
CVE-2026-40260MEDIUM5.3pypdf is a free and open-source pure-python PDF library. In versions prior to 6.10.0, manipulated XMP metadata entity de...
CVE-2026-40255MEDIUM6.1AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In @adonisjs/http-server version...
CVE-2026-40253MEDIUM6.1openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. In versions 3.26.0 and below, the BER/DER deco...
CVE-2026-40249MEDIUM5.3free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the PUT...
CVE-2026-35469MEDIUM6.5spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame...
CVE-2026-34164MEDIUM4.9Valtimo is an open-source business process automation platform. In versions 13.0.0 through 13.21.0, the InboxHandlingSer...
CVE-2026-33472MEDIUM4.8Cryptomator is an open-source client-side encryption application for cloud storage. Version 1.19.1 contains a logic flaw...
CVE-2026-40899MEDIUM6.5DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a JDBC paramete...
CVE-2026-24749MEDIUM5.3The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-r...
CVE-2026-37100MEDIUM6.5An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App: ...
CVE-2026-37346MEDIUM4.7SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_a...
CVE-2026-2840MEDIUM6.4The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2026-6410MEDIUM5.3@fastify/static versions 8.0.0 through 9.1.0 allow path traversal when directory listing is enabled via the list option....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now