2026 CVE Vulnerabilities

43,274 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-14822MEDIUM5.3The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of i...
CVE-2026-14561MEDIUM6.5The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confiden...
CVE-2026-14315MEDIUM6.5The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of i...
CVE-2026-14292MEDIUM5.4The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in t...
CVE-2026-13729MEDIUM4.3The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on some of its administrat...
CVE-2026-13604MEDIUM5.3The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emit...
CVE-2026-13329MEDIUM6.5The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce va...
CVE-2026-12966MEDIUM5.3The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted ...
CVE-2026-12696MEDIUM5.4The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it in...
CVE-2026-7623MEDIUM6.4The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Stored Cros...
CVE-2026-15403MEDIUM4.9The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection via the 'field' parame...
CVE-2026-13362MEDIUM6.4The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_...
CVE-2026-54909MEDIUM5.3pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed...
CVE-2026-54785MEDIUM6.2gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 unti...
CVE-2026-54768MEDIUM6.9WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPassword...
CVE-2026-53573MEDIUM4.8GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsaf...
CVE-2026-45377MEDIUM6.5Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3...
CVE-2026-45376MEDIUM5.5Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3...
CVE-2026-45330MEDIUM4.9Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3...
CVE-2026-52371MEDIUM6.5A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticat...
CVE-2026-52232MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150-8T2F Switch 2.2.0D Build...
CVE-2026-45086MEDIUM5.4Decidim is a participatory democracy framework. From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a partici...
CVE-2026-65841MEDIUM5.3Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTa...
CVE-2026-62324MEDIUM5.4Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElem...
CVE-2026-53551MEDIUM6.9free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the free5GC AUSF (Authentication Server...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now