2026 CVE Vulnerabilities

50,909 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-39392MEDIUM4.8CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-39391MEDIUM4.8CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-39390MEDIUM4.8CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-35023MEDIUM5.3Wimi Teamwork On-Premises versions prior to 8.2.0 contain an insecure direct object reference vulnerability in the previ...
CVE-2026-31411MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: atm: fix crash due to unvalidated vcc pointer ...
CVE-2026-2509MEDIUM6.4The Page Builder: Pagelayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget's Cu...
CVE-2026-5600MEDIUM4.3A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact...
CVE-2026-5301MEDIUM6.1Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated attackers to take over the serv...
CVE-2026-28261MEDIUM5.5Dell Elastic Cloud Storage, version 3.8.1.7 and prior, and Dell ObjectScale, versions prior to 4.1.0.3 and version 4.2.0...
CVE-2026-24511MEDIUM4.4Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.0, contains a generation o...
CVE-2026-2481MEDIUM6.4The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site ...
CVE-2026-28264MEDIUM5.5Dell PowerProtect Agent Service, version(s) prior to 20.1, contain(s) an Incorrect Permission Assignment for Critical Re...
CVE-2026-1865MEDIUM6.5The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom U...
CVE-2026-1673MEDIUM4.3The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnera...
CVE-2026-1672MEDIUM6.5The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnera...
CVE-2026-4303MEDIUM6.4The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
CVE-2026-4300MEDIUM6.4The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Loading Label' setting in al...
CVE-2026-4073MEDIUM6.4The pdfl.io plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pdflio' shortcode in all versions...
CVE-2026-4025MEDIUM6.4The PrivateContent Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' shortcode attr...
CVE-2026-39716MEDIUM5.3Missing Authorization vulnerability in CKThemes Flipmart flipmart allows Exploiting Incorrectly Configured Access Contro...
CVE-2026-39715MEDIUM5.3Missing Authorization vulnerability in AnyTrack AnyTrack Affiliate Link Manager anytrack-affiliate-link-manager allows E...
CVE-2026-39714MEDIUM5.3Missing Authorization vulnerability in G5Theme G5Plus April g5plus-april allows Exploiting Incorrectly Configured Access...
CVE-2026-39713MEDIUM5.3Missing Authorization vulnerability in mailercloud Mailercloud – Integrate webforms and synchronize website contacts mai...
CVE-2026-39712MEDIUM5.3Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in tagDiv tagDiv Composer td...
CVE-2026-39711MEDIUM5.3Insertion of Sensitive Information Into Sent Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allow...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now