2026 CVE Vulnerabilities

50,889 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-33005MEDIUM4.3Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web se...
CVE-2026-4114MEDIUM6.6Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin ...
CVE-2026-34757MEDIUM4.4LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ...
CVE-2026-3005MEDIUM6.4The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' sho...
CVE-2026-2519MEDIUM5.3The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation v...
CVE-2026-24661MEDIUM6.5Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which all...
CVE-2026-21388MEDIUM6.5Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which all...
CVE-2026-4901MEDIUM6.5AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker...
CVE-2026-34538MEDIUM6.5Apache Airflow versions 3.0.0 through 3.1.8 DagRun wait endpoint returns XCom result values even to users who only have ...
CVE-2026-5848MEDIUM4.7A vulnerability was found in jeecgboot JimuReport up to 2.3.0. The affected element is the function DriverManager.getCon...
CVE-2026-5847MEDIUM4.3A vulnerability has been found in code-projects Movie Ticketing System 1.0. Impacted is an unknown function of the file ...
CVE-2026-5840MEDIUM4.7A security flaw has been discovered in PHPGurukul News Portal Project 4.1. Impacted is an unknown function of the file /...
CVE-2026-5839MEDIUM4.7A vulnerability was identified in PHPGurukul News Portal Project 4.1. This issue affects some unknown processing of the ...
CVE-2026-5838MEDIUM4.7A vulnerability was determined in PHPGurukul News Portal Project 4.1. This vulnerability affects unknown code of the fil...
CVE-2026-5742MEDIUM6.4The UsersWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.2.60. Th...
CVE-2026-4336MEDIUM6.4The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all vers...
CVE-2026-5833MEDIUM5.3A security vulnerability has been detected in awwaiid mcp-server-taskwarrior up to 1.0.1. This impacts the function serv...
CVE-2026-5357MEDIUM6.4The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'w...
CVE-2026-4429MEDIUM6.4The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_name' and 'fil...
CVE-2026-4124MEDIUM5.4The Ziggeo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1. The ...
CVE-2026-3574MEDIUM4.4The Experto Dashboard for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
CVE-2026-3568MEDIUM4.3The MStore API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includ...
CVE-2026-5831MEDIUM6.3A security flaw has been discovered in Agions taskflow-ai up to 2.1.8. This impacts an unknown function of the file src/...
CVE-2026-5826MEDIUM4.3A flaw has been found in code-projects Simple IT Discussion Forum 1.0. This issue affects some unknown processing of the...
CVE-2026-5825MEDIUM4.3A vulnerability was detected in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now