2026 CVE Vulnerabilities

43,274 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-10774MEDIUM6.5Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/blue...
CVE-2026-68583MEDIUM5.4luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field th...
CVE-2026-12231MEDIUM6.4The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_info...
CVE-2026-18573MEDIUM6.5A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authoriza...
CVE-2026-18572MEDIUM6.5Keycloak provides authorization services that allow administrators to restrict access to resources based on time policie...
CVE-2026-18570MEDIUM5.4A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This componen...
CVE-2026-16292MEDIUM5.4The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-meta...
CVE-2026-16291MEDIUM4.3The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user befo...
CVE-2026-16273MEDIUM4.6The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field ...
CVE-2026-16064MEDIUM5.4The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the o...
CVE-2026-16063MEDIUM5.4The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline cont...
CVE-2026-16062MEDIUM6.6The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-co...
CVE-2026-16042MEDIUM4.3The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowin...
CVE-2026-15385MEDIUM5.4The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-m...
CVE-2026-15248MEDIUM5.5The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment ...
CVE-2026-14938MEDIUM4.3The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation be...
CVE-2026-14864MEDIUM5.4The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its s...
CVE-2026-14841MEDIUM6.1The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before refle...
CVE-2026-14817MEDIUM6.8The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through cer...
CVE-2026-13389MEDIUM6.5The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST ...
CVE-2026-11872MEDIUM4.3The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in ...
CVE-2026-9335MEDIUM6.5A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improp...
CVE-2026-67353MEDIUM6.9guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimit...
CVE-2026-67339MEDIUM6.9guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cUR...
CVE-2026-67338MEDIUM6.1JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to vali...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now