2026 CVE Vulnerabilities

50,404 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-6203MEDIUM6.1The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in versions up to and including 5...
CVE-2026-39979MEDIUM6.5jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() AP...
CVE-2026-39956MEDIUM6.1jq is a command-line JSON processor. In commits after 69785bf77f86e2ea1b4a20ca86775916889e91c9, the _strindices builtin ...
CVE-2026-6220MEDIUM4.7A vulnerability was identified in HummerRisk up to 1.5.0. This vulnerability affects the function ServerService.addServe...
CVE-2026-40312MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-1...
CVE-2026-40311MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below 7.1.2-19 a...
CVE-2026-40310MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below both 7.1.2...
CVE-2026-40183MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-1...
CVE-2026-40169MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-1...
CVE-2026-34238MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7....
CVE-2026-33947MEDIUM5.5jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sor...
CVE-2026-33902MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7....
CVE-2026-6219MEDIUM5.3A vulnerability was determined in aandrew-me ytDownloader up to 3.20.2. This affects the function child_process.exec of ...
CVE-2026-6218MEDIUM5.3A vulnerability was found in aandrew-me ytDownloader up to 3.20.2. Affected by this issue is the function createTextNode...
CVE-2026-33899MEDIUM5.3ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-1...
CVE-2026-33740MEDIUM5.4EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Em...
CVE-2026-31280MEDIUM6.5An issue in the Bluetooth RFCOMM service of Parani M10 Motorcycle Intercom v2.1.3 allows unauthorized attackers to cause...
CVE-2026-26460MEDIUM6.1A HTML Injection vulnerability exists in the Dashboard module of Vtiger CRM 8.4.0. The application fails to properly neu...
CVE-2026-6215MEDIUM6.3A weakness has been identified in DbGate up to 7.1.4. The impacted element is the function apiServerUrl1 of the file pac...
CVE-2026-6202MEDIUM6.3A security flaw has been discovered in code-projects Easy Blog Site 1.0. This affects an unknown function of the file po...
CVE-2026-6201MEDIUM5.4A vulnerability was identified in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the fi...
CVE-2026-33657MEDIUM5.4EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have a stored HTML inje...
CVE-2026-33534MEDIUM4.3EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have an authenticated S...
CVE-2026-40041MEDIUM5.3Pachno 1.0.6 contains a cross-site request forgery vulnerability that allows attackers to perform arbitrary actions in a...
CVE-2026-6191MEDIUM6.3A vulnerability was determined in itsourcecode Construction Management System 1.0. This affects an unknown function of t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now