2026 CVE Vulnerabilities

51,063 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-2726MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.8.7, 18.9 before 18.9.3, and ...
CVE-2026-27659MEDIUM4.6Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to properly validate ...
CVE-2026-27656MEDIUM6.1Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate ...
CVE-2026-27046MEDIUM6.5Missing Authorization vulnerability in Kaira StoreCustomizer woocustomizer allows Exploiting Incorrectly Configured Acce...
CVE-2026-26233MEDIUM6.5Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to rate limit login r...
CVE-2026-25645MEDIUM5.5Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a...
CVE-2026-25469MEDIUM6.5Missing Authorization vulnerability in ViaBill for WooCommerce ViaBill – WooCommerce viabill-woocommerce allows Exploiti...
CVE-2026-25465MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople CP Mult...
CVE-2026-25462MEDIUM6.5Missing Authorization vulnerability in avalex avalex avalex allows Exploiting Incorrectly Configured Access Control Secu...
CVE-2026-25460MEDIUM6.3Missing Authorization vulnerability in LiquidThemes Ave Core ave-core allows Exploiting Incorrectly Configured Access Co...
CVE-2026-25455MEDIUM6.5Missing Authorization vulnerability in PickPlugins Product Slider for WooCommerce woocommerce-products-slider allows Exp...
CVE-2026-25454MEDIUM6.5Missing Authorization vulnerability in MVPThemes The League the-league allows Exploiting Incorrectly Configured Access C...
CVE-2026-25437MEDIUM6.5Missing Authorization vulnerability in سید محمدامین هاشمی GZSEO gzseo allows Exploiting Incorrectly Configured Access Co...
CVE-2026-25430MEDIUM6.5Missing Authorization vulnerability in CRM Perks Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja...
CVE-2026-25417MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss ProfileG...
CVE-2026-25398MEDIUM6.5Missing Authorization vulnerability in Webilia Inc. Vertex Addons for Elementor addons-for-elementor-builder allows Expl...
CVE-2026-25390MEDIUM6.5Missing Authorization vulnerability in Saad Iqbal New User Approve new-user-approve allows Exploiting Incorrectly Config...
CVE-2026-25365MEDIUM6.5Missing Authorization vulnerability in Özgür KARALAR Kargo Takip kargo-takip-turkiye allows Exploiting Incorrectly Confi...
CVE-2026-25355MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Sanzo san...
CVE-2026-25344MEDIUM6.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RadiusTheme Review Schema re...
CVE-2026-25339MEDIUM6.5Insertion of Sensitive Information Into Sent Data vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allo...
CVE-2026-25328MEDIUM6.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org Product File...
CVE-2026-25327MEDIUM6.5Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Explo...
CVE-2026-25034MEDIUM6.5Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorr...
CVE-2026-25009MEDIUM6.5Missing Authorization vulnerability in raratheme Education Zone education-zone allows Exploiting Incorrectly Configured ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now