2026 CVE Vulnerabilities

64,785 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-90922MEDIUM5.3The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported b...
CVE-2026-86824MEDIUM4.8The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy a...
CVE-2026-86788MEDIUM6.8The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the s...
CVE-2026-50604MEDIUM4.9A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The ...
CVE-2026-92839MEDIUM4.3Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the applicat...
CVE-2026-86311MEDIUM6.4The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scrip...
CVE-2026-50603MEDIUM4.9A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The ...
CVE-2026-89064MEDIUM5.3The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in versi...
CVE-2026-61589MEDIUM6.3djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ...
CVE-2026-61588MEDIUM6.5djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ...
CVE-2026-92598MEDIUM6.5Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain...
CVE-2026-92597MEDIUM6.5Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a commen...
CVE-2026-92595MEDIUM5.9Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAcc...
CVE-2026-92591MEDIUM5.9Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes...
CVE-2026-92590MEDIUM5.4Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields...
CVE-2026-92589MEDIUM4.3Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder ...
CVE-2026-92588MEDIUM4.4n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endp...
CVE-2026-92587MEDIUM5n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relativ...
CVE-2026-92586MEDIUM4.3AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the se...
CVE-2026-92585MEDIUM4.3AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the ...
CVE-2026-92584MEDIUM6.1AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticat...
CVE-2026-92583MEDIUM6.5AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate...
CVE-2026-92581MEDIUM4.3In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowin...
CVE-2026-92579MEDIUM5.4In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without ...
CVE-2026-89034MEDIUM6.5TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low En...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now