2026 CVE Vulnerabilities

53,108 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-28104MEDIUM6.5Missing Authorization vulnerability in Aryan Shirani Bid Abadi Site Suggest site-suggest allows Accessing Functionality ...
CVE-2026-28078MEDIUM4.9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Stylemix uListing ulisti...
CVE-2026-28071MEDIUM6.3Missing Authorization vulnerability in PixFort pixfort Core pixfort-core allows Exploiting Incorrectly Configured Access...
CVE-2026-28038MEDIUM6.5Missing Authorization vulnerability in Brainstorm_Force Ultimate Addons for WPBakery Page Builder ultimate_vc_addons all...
CVE-2026-28036MEDIUM6.4Server-Side Request Forgery (SSRF) vulnerability in SkatDesign Ratatouille ratatouille allows Server Side Request Forger...
CVE-2026-27982MEDIUM6.1An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled...
CVE-2026-27411MEDIUM5.4Guessable CAPTCHA vulnerability in jp-secure SiteGuard WP Plugin siteguard allows Functionality Bypass.This issue affect...
CVE-2026-27362MEDIUM6.5Missing Authorization vulnerability in kamleshyadav WP Bakery Autoresponder Addon vc-autoresponder-addon allows Exploiti...
CVE-2026-27354MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Woo...
CVE-2026-27344MEDIUM5.9Missing Authorization vulnerability in inseriswiss inseri core inseri-core allows Exploiting Incorrectly Configured Acce...
CVE-2026-23799MEDIUM6.5Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control S...
CVE-2026-23546MEDIUM6.5Insertion of Sensitive Information Into Sent Data vulnerability in RadiusTheme Classified Listing classified-listing all...
CVE-2026-22459MEDIUM6.5Missing Authorization vulnerability in Blend Media WordPress CTA easy-sticky-sidebar allows Exploiting Incorrectly Confi...
CVE-2026-3523MEDIUM4.9The Apocalypse Meow plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, ...
CVE-2026-3034MEDIUM6.4The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _ob_spacera...
CVE-2026-2899MEDIUM6.5The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and ...
CVE-2026-29125MEDIUM4.7IDC SFX2100 Satalite Recievers set the `/etc/resolv.conf` file to be world-writable by any local user, allowing DNS reso...
CVE-2026-29122MEDIUM5.5International Data Casting (IDC) SFX2100 satellite receiver comes with the `/bin/date` utility installed with the setuid...
CVE-2026-22052MEDIUM4.3ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Success...
CVE-2026-2297MEDIUM5.7The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (...
CVE-2026-29086MEDIUM5.4Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, the setCo...
CVE-2026-29085MEDIUM6.5Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when usin...
CVE-2026-27898MEDIUM5.4Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to versi...
CVE-2026-27801MEDIUM5.9Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden ve...
CVE-2026-22040MEDIUM5.3NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, by generating a combined traffi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now