2026 CVE Vulnerabilities

52,167 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-63239MEDIUM5.4A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 bucke...
CVE-2026-63238MEDIUM6.5An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, incl...
CVE-2026-63237MEDIUM4.8A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled s...
CVE-2026-63236LOW3.7An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name,...
CVE-2026-63235LOW3.7An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forcibly terminate the se...
CVE-2026-63234CRITICAL9.9A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject thro...
CVE-2026-63233CRITICAL9.9A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject thro...
CVE-2026-63232CRITICAL9.9A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject thro...
CVE-2026-63231HIGH8.1A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based...
CVE-2026-63230CRITICAL9.1A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read ...
CVE-2026-63229CRITICAL9.1A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-...
CVE-2026-63228LOW2.6An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content ...
CVE-2026-63227CRITICAL9.9An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCOR...
CVE-2026-14300HIGH8.1The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bin...
CVE-2026-14234HIGH7.1The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowin...
CVE-2026-14224MEDIUM5.4The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data...
CVE-2026-13692MEDIUM5.3The PayU CommercePro Plugin WordPress plugin before 3.9.0 does not verify the payment-gateway signature before applying ...
CVE-2026-13690HIGH7.4The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor log...
CVE-2026-13605MEDIUM6.8The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox ca...
CVE-2026-13423CRITICAL9.8The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauth...
CVE-2026-11974HIGH8.6The wp-media-folder-addon WordPress plugin before 4.1.7 does not validate a user-supplied parameter before using it in a...
CVE-2026-11351MEDIUM5.3The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API e...
CVE-2026-18072CRITICAL9.8The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to ...
CVE-2026-5626MEDIUM4.3The Survey Form Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability chec...
CVE-2026-15344MEDIUM4.9The WP Photo Album Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'table' parameter in all ver...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now