2026 CVE Vulnerabilities

52,241 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-30842MEDIUM4.3Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, Wallos allows an authenti...
CVE-2026-30841MEDIUM6.1Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, passwordreset.php outputs...
CVE-2026-30839MEDIUM4.3Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, testwebhooknotifications....
CVE-2026-30830MEDIUM6.1Defuddle cleans up HTML pages. Prior to version 0.9.0, the _findContentBySchemaText method in src/defuddle.ts interpolat...
CVE-2026-30829MEDIUM5.3Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and...
CVE-2026-30825MEDIUM6.5hoppscotch is an open source API development ecosystem. Prior to version 2026.2.1, the DELETE /v1/access-tokens/revoke e...
CVE-2026-27797MEDIUM5.3Homarr is an open-source dashboard. Prior to version 1.54.0, an unauthenticated Server-Side Request Forgery (SSRF) vulne...
CVE-2026-2722MEDIUM4.8The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up...
CVE-2026-2721MEDIUM4.8The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up...
CVE-2026-2494MEDIUM4.3The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Cross-Site Request Forgery...
CVE-2026-2488MEDIUM4.3The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message delet...
CVE-2026-2431MEDIUM6.1The CM Custom Reports plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date_from' and 'date...
CVE-2026-2429MEDIUM4.9The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'ce_venue_name' CSV field in the `on_sa...
CVE-2026-1902MEDIUM6.4The Hammas Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'apix' parameter in the 'h...
CVE-2026-1650MEDIUM5.3The MDJM Event Management plugin for WordPress is vulnerable to unauthorized data modification due to a missing capabili...
CVE-2026-25073MEDIUM5.4XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a stored cross-site scripting vulnerabil...
CVE-2026-2371MEDIUM5.3The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Insecure Direct Object Referenc...
CVE-2026-1981MEDIUM4.3The HUMN-1 AI Website Scanner & Human Certification by Winston AI plugin for WordPress is vulnerable to unauthorized mod...
CVE-2026-1644MEDIUM4.3The WP Frontend Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2026-30238MEDIUM6.1Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.155, 25.0.88, a...
CVE-2026-30237MEDIUM6.1Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.155, 25.0.88, a...
CVE-2026-27142MEDIUM6.1Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t...
CVE-2026-27138MEDIUM5.9Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the ...
CVE-2026-30835MEDIUM5.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-30233MEDIUM4.3OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authorization fl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now