2026 CVE Vulnerabilities

52,241 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-30838MEDIUM6.1league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by i...
CVE-2026-29787MEDIUM5.3mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.21.0, the /api/health/d...
CVE-2026-29786MEDIUM6.3node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that p...
CVE-2026-29781MEDIUM6.5Sliver is a command and control framework that uses a custom Wireguard netstack. In versions from 1.7.3 and prior, a vul...
CVE-2026-29780MEDIUM5.5eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well...
CVE-2026-29778MEDIUM6.5pyLoad is a free and open-source download manager written in Python. From version 0.5.0b3.dev13 to 0.5.0b3.dev96, the ed...
CVE-2026-29771MEDIUM6.5Netmaker makes networks with WireGuard. Prior to version 1.2.0, the /api/server/shutdown endpoint allows termination of ...
CVE-2026-29190MEDIUM5.3Karapace is an open-source implementation of Kafka REST and Schema Registry. Prior to version 6.0.0, there is a Path Tra...
CVE-2026-29076MEDIUM5.9cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.37.0, cpp-httplib u...
CVE-2026-3664MEDIUM5.5A vulnerability was determined in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::compound_docum...
CVE-2026-29184MEDIUM6.5Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template c...
CVE-2026-2433MEDIUM6.1The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to DOM-Ba...
CVE-2026-2420MEDIUM4.4The LotekMedia Popup Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in a...
CVE-2026-1825MEDIUM6.4The Show YouTube video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'syv' shortcod...
CVE-2026-1824MEDIUM6.4The Infomaniak Connect for OpenID plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'endpoint_lo...
CVE-2026-1823MEDIUM6.4The Consensus Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's consensus shortco...
CVE-2026-1820MEDIUM6.4The Media Library Alt Text Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bv...
CVE-2026-1805MEDIUM6.4The DA Media GigList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's damedia_giglist ...
CVE-2026-1574MEDIUM6.4The MyQtip – easy qTip2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `myqtip` shor...
CVE-2026-1569MEDIUM6.4The Wueen plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wueen-blocket` shortcode i...
CVE-2026-1087MEDIUM4.3The Guardian News Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2026-1086MEDIUM4.3The Font Pairing Preview For Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi...
CVE-2026-1085MEDIUM4.3The True Ranker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2...
CVE-2026-1073MEDIUM4.3The Purchase Button For Affiliate Link plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions ...
CVE-2026-1071MEDIUM4.4The Carta Online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now