2026 CVE Vulnerabilities

53,017 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-2431MEDIUM6.1The CM Custom Reports plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date_from' and 'date...
CVE-2026-2429MEDIUM4.9The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'ce_venue_name' CSV field in the `on_sa...
CVE-2026-1902MEDIUM6.4The Hammas Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'apix' parameter in the 'h...
CVE-2026-1650MEDIUM5.3The MDJM Event Management plugin for WordPress is vulnerable to unauthorized data modification due to a missing capabili...
CVE-2026-25073MEDIUM5.4XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a stored cross-site scripting vulnerabil...
CVE-2026-2371MEDIUM5.3The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Insecure Direct Object Referenc...
CVE-2026-1981MEDIUM4.3The HUMN-1 AI Website Scanner & Human Certification by Winston AI plugin for WordPress is vulnerable to unauthorized mod...
CVE-2026-1644MEDIUM4.3The WP Frontend Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2026-30238MEDIUM6.1Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.155, 25.0.88, a...
CVE-2026-30237MEDIUM6.1Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.155, 25.0.88, a...
CVE-2026-27142MEDIUM6.1Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t...
CVE-2026-27138MEDIUM5.9Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the ...
CVE-2026-30835MEDIUM5.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-30233MEDIUM4.3OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authorization fl...
CVE-2026-30231MEDIUM5.3Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1....
CVE-2026-30228MEDIUM4.9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-30227MEDIUM5.3MimeKit is a C# library which may be used for the creation and parsing of messages using the Multipurpose Internet Mail ...
CVE-2026-30225MEDIUM4.3OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authentication c...
CVE-2026-30224MEDIUM5.4OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, OliveTin does not r...
CVE-2026-29791MEDIUM6.5Agentgateway is an open source data plane for agentic AI connectivity within or across any agent framework or environmen...
CVE-2026-29790MEDIUM5.3dbt-common is the shared common utilities for dbt-core and adapter implementations use. Prior to versions 1.34.2 and 1.3...
CVE-2026-30847MEDIUM6.5Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the notificationUsers publicatio...
CVE-2026-30843MEDIUM6.5Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 have a critical Insecure Direct Object Ref...
CVE-2026-3419MEDIUM5.3Fastify incorrectly accepts malformed `Content-Type` headers containing trailing characters after the subtype token, in ...
CVE-2026-30833MEDIUM5.3Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.1...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now