2026 CVE Vulnerabilities

51,104 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-4733MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue affect...
CVE-2026-4626MEDIUM5.4A vulnerability has been found in projectworlds Lawyer Management System 1.0. This impacts an unknown function of the fi...
CVE-2026-33308MEDIUM5.9Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Prior to version 0.13.0, code for client certificate verifi...
CVE-2026-3079MEDIUM6.5The LearnDash LMS plugin for WordPress is vulnerable to blind time-based SQL Injection via the 'filters[orderby_order]' ...
CVE-2026-33320MEDIUM6.2Dasel is a command-line tool and library for querying, modifying, and transforming data structures. Starting in version ...
CVE-2026-33290MEDIUM4.3WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.10.0, an authorization flaw in updateComment al...
CVE-2026-4614MEDIUM6.3A vulnerability was determined in itsourcecode sanitize or validate this input 1.0. This issue affects some unknown proc...
CVE-2026-4056MEDIUM5.4The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a miss...
CVE-2026-33252MEDIUM6.5The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.1, the Go SDK's Streamable HTTP transport accepted...
CVE-2026-33173MEDIUM5.3Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a...
CVE-2026-33170MEDIUM6.1Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to v...
CVE-2026-33169MEDIUM5.3Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. `NumberToD...
CVE-2026-4066MEDIUM4.3The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch...
CVE-2026-3225MEDIUM4.3The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized deletion of quiz question answe...
CVE-2026-33167MEDIUM6.1Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8....
CVE-2026-2412MEDIUM6.5The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to SQL Injection via the 'merged_question' parameter...
CVE-2026-32279MEDIUM6.8Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the...
CVE-2026-32278MEDIUM4.8Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the...
CVE-2026-29111MEDIUM5.5systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call...
CVE-2026-27646MEDIUM6.1OpenClaw versions prior to 2026.3.7 contain a sandbox escape vulnerability in the /acp spawn command that allows authori...
CVE-2026-27183MEDIUM5.3OpenClaw versions prior to 2026.3.7 contain a shell approval gating bypass vulnerability in system.run dispatch-wrapper ...
CVE-2026-4597MEDIUM6.3A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. Impacted is the function selectAll of the ...
CVE-2026-23488MEDIUM5.3Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the /api/v1/comment/create endpoint has an una...
CVE-2026-23487MEDIUM6.5Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an IDOR vulnerability where user.deta...
CVE-2026-23486MEDIUM5.3Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, a publicly accessible endpoint exposes all use...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now