2026 CVE Vulnerabilities

52,080 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-31915MEDIUM5.3Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Contr...
CVE-2026-31864MEDIUM6.8JumpServer is an open source bastion host and an operation and maintenance security audit system. a Server-Side Template...
CVE-2026-31798MEDIUM5JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v4.10.16-lts,...
CVE-2026-30961MEDIUM4.3Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, the chunke...
CVE-2026-30955MEDIUM6.5Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An API end...
CVE-2026-30943MEDIUM4.1Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An insuffi...
CVE-2026-30915MEDIUM4.3SFTPGo is an open source, event-driven file transfer solution. SFTPGo versions before v2.7.1 contain an input validation...
CVE-2026-2888MEDIUM5.3The Formidable Forms plugin for WordPress is vulnerable to an authorization bypass through user-controlled key in all ve...
CVE-2026-2879MEDIUM5.4The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including...
CVE-2026-2859MEDIUM4.3Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows...
CVE-2026-2673MEDIUM6.5Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key ex...
CVE-2026-2257MEDIUM6.4The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including...
CVE-2026-24097MEDIUM4.3Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows...
CVE-2026-23943MEDIUM5.3Improper Handling of Highly Compressed Data (Compression Bomb) vulnerability in Erlang OTP ssh (ssh_transport modules) a...
CVE-2026-23942MEDIUM5.4Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (ssh_sftpd mo...
CVE-2026-23940MEDIUM6.5Uncontrolled Resource Consumption vulnerability in hexpm hexpm/hexpm allows Excessive Allocation. Publishing an oversize...
CVE-2026-22216MEDIUM5.3wpDiscuz before 7.6.47 contains a missing rate limiting vulnerability that allows unauthenticated attackers to subscribe...
CVE-2026-22215MEDIUM5.4wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability in the getFollowsPage() function that allows ...
CVE-2026-22210MEDIUM6.1wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability that allows attackers to inject malicious code thro...
CVE-2026-22209MEDIUM5.5wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability in the customCss field that allows administrators t...
CVE-2026-22204MEDIUM5.3wpDiscuz before 7.6.47 contains an email header injection vulnerability that allows attackers to manipulate mail recipie...
CVE-2026-22203MEDIUM6.9wpDiscuz before 7.6.47 contains an information disclosure vulnerability that allows administrators to inadvertently expo...
CVE-2026-22202MEDIUM6.5wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments ...
CVE-2026-22201MEDIUM6.9wpDiscuz before 7.6.47 contains an IP spoofing vulnerability in the getIP() function that allows attackers to bypass IP-...
CVE-2026-22191MEDIUM5.2Beghelli Sicuro24 SicuroWeb contains a template injection vulnerability that allows attackers to inject arbitrary Angula...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now