2026 CVE Vulnerabilities

53,091 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-28080MEDIUM4.3Missing Authorization vulnerability in Rank Math Rank Math SEO PRO allows Exploiting Incorrectly Configured Access Contr...
CVE-2026-1468MEDIUM5.1QuickCMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. An attacker can craft special website, w...
CVE-2026-2830MEDIUM6.1The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to Reflect...
CVE-2026-29183MEDIUM6.1SiYuan is a personal knowledge management system. Prior to version 3.5.9, an unauthenticated reflected XSS vulnerability...
CVE-2026-29049MEDIUM4.3melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cach...
CVE-2026-29048MEDIUM6.1HumHub is an Open Source Enterprise Social Network. In version 1.18.0, a cross-site scripting vulnerability was identifi...
CVE-2026-29038MEDIUM6.1changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, there is a reflected c...
CVE-2026-28804MEDIUM5.3pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability...
CVE-2026-1128MEDIUM4.3The WP eCommerce WordPress plugin through 3.15.1 does not have CSRF check in place when deleting coupons, which could al...
CVE-2026-29084MEDIUM4.6Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, th...
CVE-2026-29061MEDIUM5.4Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a ...
CVE-2026-29060MEDIUM5Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a ...
CVE-2026-28685MEDIUM6.5Kimai is a web-based multi-user time-tracking application. Prior to version 2.51.0, "GET /api/invoices/{id}" only checks...
CVE-2026-28682MEDIUM6.4Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, th...
CVE-2026-28675MEDIUM5.3OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version...
CVE-2026-28509MEDIUM5.4LangBot is a global IM bot platform designed for LLMs. Prior to version 4.8.7, LangBot’s web UI renders user-supplied ra...
CVE-2026-28428MEDIUM5.3Talishar is a fan-made Flesh and Blood project. Prior to commit a9c218e, an authentication bypass vulnerability in Talis...
CVE-2026-27605MEDIUM5.4Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-25877MEDIUM6.5Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-27807MEDIUM4.9MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.4, MarkUs allows...
CVE-2026-25962MEDIUM6.5MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.4, MarkUs curren...
CVE-2026-3616MEDIUM6.3A vulnerability was detected in DefaultFuction Jeson Customer Relationship Management System 1.0.0. Impacted is an unkno...
CVE-2026-3610MEDIUM4.3A vulnerability was found in HSC Cybersecurity Mailinspector up to 5.3.2-3. Affected by this issue is some unknown funct...
CVE-2026-2589MEDIUM5.3The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Sensitive Information Exposure ...
CVE-2026-28726MEDIUM4.3Sensitive information disclosure due to improper access control. The following products are affected: Acronis Cyber Prot...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now