2026 CVE Vulnerabilities

53,146 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-28556MEDIUM5.4wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to move, merge,...
CVE-2026-28555MEDIUM5.3wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to close or reo...
CVE-2026-28554MEDIUM5.3wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to approve or u...
CVE-2026-3010MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip T...
CVE-2026-1542MEDIUM6.5The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated...
CVE-2026-28426MEDIUM5.4Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, stored XSS ...
CVE-2026-28424MEDIUM6.5Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email ...
CVE-2026-27759MEDIUM5.3Featured Image from Content (featured-image-from-content) WordPress plugin versions prior to 1.7 contain an authenticate...
CVE-2026-28420MEDIUM4.4Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an ou...
CVE-2026-28419MEDIUM6.6Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim'...
CVE-2026-28418MEDIUM5.5Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds r...
CVE-2026-28415MEDIUM4.7Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the _redirect_to_target(...
CVE-2026-28407MEDIUM5.3malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior ...
CVE-2026-27167MEDIUM5.9Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version ...
CVE-2026-28352MEDIUM6.5Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In vers...
CVE-2026-28351MEDIUM5.3pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.4, an attacker who uses this vulnerability...
CVE-2026-28338MEDIUM6.1PMD is an extensible multilanguage static code analyzer. Prior to version 7.22.0, PMD's `vbhtml` and `yahtml` report for...
CVE-2026-28288MEDIUM5.3Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-exi...
CVE-2026-28272MEDIUM4.8Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks Email Protection Gateway...
CVE-2026-28271MEDIUM6.5Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration functional...
CVE-2026-3255MEDIUM6.5HTTP::Session2 versions before 1.12 for Perl for Perl may generate weak session ids using the rand() function. The HTTP...
CVE-2026-28354MEDIUM6.5ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are vulne...
CVE-2026-27824MEDIUM5.3calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9....
CVE-2026-27810MEDIUM6.4calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9....
CVE-2026-27793MEDIUM6.5Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.1.0, the `G...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now