2026 CVE Vulnerabilities

50,066 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-33472MEDIUM4.8Cryptomator is an open-source client-side encryption application for cloud storage. Version 1.19.1 contains a logic flaw...
CVE-2026-40899MEDIUM6.5DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a JDBC paramete...
CVE-2026-24749MEDIUM5.3The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-r...
CVE-2026-37100MEDIUM6.5An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App: ...
CVE-2026-37346MEDIUM4.7SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_a...
CVE-2026-2840MEDIUM6.4The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2026-6410MEDIUM5.3@fastify/static versions 8.0.0 through 9.1.0 allow path traversal when directory listing is enabled via the list option....
CVE-2026-4160MEDIUM5.3The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne...
CVE-2026-6414MEDIUM5.9@fastify/static versions 8.0.0 through 9.1.0 decode percent-encoded path separators (%2F) before filesystem resolution, ...
CVE-2026-3369MEDIUM5.4The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2026-0718MEDIUM5.3The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthor...
CVE-2026-41034MEDIUM5ONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.c...
CVE-2026-41030MEDIUM6.2In ONLYOFFICE DesktopEditors before 9.3.0, the update service allows attackers to perform actions on files with SYSTEM p...
CVE-2026-3995MEDIUM4.4The OPEN-BRAIN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'API Key' settings field in all...
CVE-2026-3875MEDIUM6.4The BetterDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'betterdocs_feedback_form' shor...
CVE-2026-3355MEDIUM6.1The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘crsea...
CVE-2026-1572MEDIUM6.4The Livemesh Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cro...
CVE-2026-3773MEDIUM6.5The Accessibility Suite by Ability, Inc plugin for WordPress is vulnerable to SQL Injection via the 'scan_id' parameter ...
CVE-2026-3595MEDIUM5.3The Riaxe Product Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu...
CVE-2026-3581MEDIUM5.3The Basic Google Maps Placemarks plugin for WordPress is vulnerable to authorization bypass in versions up to, and inclu...
CVE-2026-3551MEDIUM4.4The Custom New User Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's admi...
CVE-2026-40118MEDIUM6.3UDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability....
CVE-2026-5070MEDIUM6.4The Vantage theme for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery block text content in versions ...
CVE-2026-4032MEDIUM6.1The CodeColorer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in 'cc' comm...
CVE-2026-3878MEDIUM6.4The WP Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdocs_options[icon_size]' parame...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now