2026 CVE Vulnerabilities

64,779 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-92932MEDIUM5.1In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in...
CVE-2026-92921MEDIUM4.9admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivatio...
CVE-2026-92920MEDIUM5.4admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain a...
CVE-2026-92904MEDIUM4.3A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_...
CVE-2026-92912MEDIUM6.5AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish key...
CVE-2026-81479MEDIUM5.8Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability. A ...
CVE-2026-81441MEDIUM4Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Functio...
CVE-2026-78296MEDIUM5.3Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing. ...
CVE-2026-92893MEDIUM4.3A flaw was found in the foreman_ansible plugin's Ansible inventory API. The controller builds its host query using an un...
CVE-2026-92611MEDIUM4.8In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at...
CVE-2026-92894MEDIUM4.3A flaw was found in the foreman_ansible plugin's Ansible override values API. The destroy action resolves the target Loo...
CVE-2026-78427MEDIUM4.3The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of...
CVE-2026-87831MEDIUM4.3The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate t...
CVE-2026-87829MEDIUM4.3The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate t...
CVE-2026-90982MEDIUM5.3@fastify/static is a Fastify plugin that serves static files from a configured root directory. In versions before 10.1.4...
CVE-2026-44940MEDIUM5.7The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecu...
CVE-2026-91019MEDIUM4.9The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payme...
CVE-2026-91016MEDIUM5.3The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published ...
CVE-2026-91015MEDIUM5.3The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX actio...
CVE-2026-91011MEDIUM6.8The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites ...
CVE-2026-91010MEDIUM4.3The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the...
CVE-2026-91009MEDIUM4.3The Active Woot Products Tables for WooCommerce. 100% FREE  WordPress plugin before 2.1.3 does not have authorisation an...
CVE-2026-90923MEDIUM6.5The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unaut...
CVE-2026-90922MEDIUM5.3The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported b...
CVE-2026-86824MEDIUM4.8The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now