2026 CVE Vulnerabilities

50,938 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-33227MEDIUM4.3Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ...
CVE-2026-3177MEDIUM5.3The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vul...
CVE-2026-4079MEDIUM6.5The SQL Chart Builder WordPress plugin before 2.3.8 does not properly escape user input as it is concatened to SQL queri...
CVE-2026-1900MEDIUM6.5The Link Whisper Free WordPress plugin before 0.9.1 has a publicly accessible REST endpoint that allows unauthenticated ...
CVE-2026-20446MEDIUM4.3In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of serv...
CVE-2026-20431MEDIUM6.5In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE ha...
CVE-2026-5719MEDIUM6.3A flaw has been found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /...
CVE-2026-5705MEDIUM4.3A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown f...
CVE-2026-35475MEDIUM6.1WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, the redirect parameter is taken directly from $_GET ...
CVE-2026-35474MEDIUM6.1WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, open redirect has been found in WeGIA webapp. The re...
CVE-2026-35473MEDIUM6.1WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the...
CVE-2026-35454MEDIUM6.5The Code Extension Marketplace is an open-source alternative to the VS Code Marketplace. Prior to 2.4.2, Zip Slip vulner...
CVE-2026-35452MEDIUM5.3WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/CloneSite/client.log.php endpoint s...
CVE-2026-35450MEDIUM5.3WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/API/check.ffmpeg.json.php endpoint ...
CVE-2026-35449MEDIUM5.3WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagnostic script has its...
CVE-2026-35444MEDIUM6.1SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel ...
CVE-2026-35441MEDIUM6.5Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL end...
CVE-2026-35413MEDIUM5.3Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, when GRAPHQL_INTROSPE...
CVE-2026-35411MEDIUM4.3Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus is vulnerabl...
CVE-2026-35410MEDIUM6.1Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, an open redirect vuln...
CVE-2026-35404MEDIUM6.1Open edX Platform enables the authoring and delivery of online learning at any scale. The view_survey endpoint accepts a...
CVE-2026-22675MEDIUM6.1OCS Inventory NG Server version 2.12.3 and prior contain a stored cross-site scripting vulnerability that allows unauthe...
CVE-2026-35472MEDIUM6.1WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the...
CVE-2026-35399MEDIUM6.1WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, a stored XSS vulnerability allows an attacker to inj...
CVE-2026-35398MEDIUM6.1WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now