2026 CVE Vulnerabilities

51,046 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-26070MEDIUM4.2EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::map<std::optiona...
CVE-2026-4877MEDIUM4.3A security flaw has been discovered in itsourcecode Payroll Management System up to 1.0. This affects an unknown functio...
CVE-2026-4876MEDIUM6.3A vulnerability was identified in itsourcecode Free Hotel Reservation System 1.0. The impacted element is an unknown fun...
CVE-2026-33343MEDIUM6.5etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9,...
CVE-2026-2389MEDIUM4.9The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versio...
CVE-2026-1032MEDIUM4.3The Conditional Menus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2026-4875MEDIUM4.7A vulnerability was determined in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknown fun...
CVE-2026-4274MEDIUM5.4Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to restrict team-leve...
CVE-2026-23398MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: icmp: fix NULL pointer dereference in icmp_tag_vali...
CVE-2026-23396MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix NULL deref in mesh_matches_loca...
CVE-2026-4263MEDIUM6.9Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other u...
CVE-2026-4262MEDIUM6.9Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other u...
CVE-2026-4849MEDIUM6.1A vulnerability was identified in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file ...
CVE-2026-4848MEDIUM4.3A vulnerability was determined in dameng100 muucmf 1.9.5.20260309. This affects an unknown function of the file /admin/e...
CVE-2026-4847MEDIUM4.3A vulnerability was found in dameng100 muucmf 1.9.5.20260309. The impacted element is an unknown function of the file /a...
CVE-2026-1890MEDIUM5.3The LeadConnector WordPress plugin before 3.0.22 does not have authorization in a REST route, allowing unauthenticated u...
CVE-2026-1430MEDIUM4.8The WP Lightbox 2 WordPress plugin before 3.0.7 does not sanitise and escape some of its settings, which could allow hig...
CVE-2026-4846MEDIUM4.3A vulnerability has been found in dameng100 muucmf 1.9.5.20260309. The affected element is an unknown function of the fi...
CVE-2026-4845MEDIUM4.3A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is an unknown function of the file /admin/Member/inde...
CVE-2026-1206MEDIUM4.3The Elementor Website Builder plugin for WordPress is vulnerable to Incorrect Authorization to Sensitive Information Exp...
CVE-2026-4389MEDIUM6.4The DSGVO snippet for Leaflet Map and its Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2026-4331MEDIUM4.3The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized data loss in all ...
CVE-2026-4281MEDIUM5.3The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to Missing Authorization in all versions up t...
CVE-2026-4278MEDIUM6.4The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sdc_menu' shortco...
CVE-2026-4335MEDIUM5.4The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment post...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now