2026 CVE Vulnerabilities

53,128 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-28772MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability in the /IDC_Logging/index.cgi endpoint of International Datacasting...
CVE-2026-28771MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in the /index.cgi endpoint of International Datacasting Corp...
CVE-2026-2732MEDIUM5.4The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capa...
CVE-2026-2363MEDIUM6.5The WP-Members Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'order_by' attribute of the...
CVE-2026-28769MEDIUM6.5A path traversal vulnerability exists in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corporatio...
CVE-2026-3242MEDIUM4.8In Concrete CMS below version 9.4.8, a rogue administrator can add stored XSS via the Switch Language block.  The Concre...
CVE-2026-3241MEDIUM4.8In Concrete CMS below version 9.4.8, a stored cross-site scripting (XSS) vulnerability exists in the "Legacy Form" block...
CVE-2026-3240MEDIUM4.8In Concrete CMS below version 9.4.8, a user with permission to edit a page with element Legacy form can perform a stored...
CVE-2026-2994MEDIUM6.8Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configu...
CVE-2026-3244MEDIUM4.8In Concrete CMS below version 9.4.8, A stored cross-site scripting (XSS) vulnerability exists in the search block where ...
CVE-2026-2292MEDIUM4.4The Morkva UA Shipping plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi...
CVE-2026-2289MEDIUM4.4The Taskbuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ...
CVE-2026-1980MEDIUM5.3The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on ...
CVE-2026-1651MEDIUM6.5The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the 'workflow_ids' para...
CVE-2026-27601MEDIUM5.9Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recur...
CVE-2026-27600MEDIUM4.3HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, the notifier functionality allows authenticat...
CVE-2026-26272MEDIUM5.4HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, a stored cross-site scripting (XSS) vulnerabi...
CVE-2026-26266MEDIUM6.1AliasVault is a privacy-first password manager with built-in email aliasing. A stored cross-site scripting (XSS) vulnera...
CVE-2026-25590MEDIUM6.1The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents...
CVE-2026-24415MEDIUM6.1OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e...
CVE-2026-21866MEDIUM5.4Dify is an open-source LLM app development platform. Prior to 1.11.2, Dify is vulnerable to a stored XSS issue when rend...
CVE-2026-1713MEDIUM5IBM MQ 9.1.0.0 through 9.1.0.33 LTS, 9.2.0.0 through 9.2.0.40 LTS, 9.3.0.0 through 9.3.0.36 LTS, 9.30.0 through 9.3.5.1 ...
CVE-2026-3494MEDIUM5.3In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configur...
CVE-2026-2606MEDIUM6.5IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix2711.1 to 11.1_Fix7 IBM webMethods API M...
CVE-2026-1265MEDIUM5.3IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to writing of sensitive Information in a log f...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now