2026 CVE Vulnerabilities

53,211 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-23548MEDIUM5.3Missing Authorization vulnerability in Designinvento DirectoryPress directorypress allows Exploiting Incorrectly Configu...
CVE-2026-23545MEDIUM6.5Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Exploiting Incorrectl...
CVE-2026-23543MEDIUM5.3Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite al...
CVE-2026-22422MEDIUM5.3Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in wpeverest Everest Forms e...
CVE-2026-22269MEDIUM4.7Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communicat...
CVE-2026-2711MEDIUM5.6A vulnerability has been found in zhutoutoutousan worldquant-miner up to 1.0.9. The impacted element is an unknown funct...
CVE-2026-2703MEDIUM5.5A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::decode_base64 ...
CVE-2026-2693MEDIUM6.5A vulnerability was determined in CoCoTeaNet CyreneAdmin up to 1.3.0. This vulnerability affects unknown code of the fil...
CVE-2026-2692MEDIUM6.5A vulnerability was found in CoCoTeaNet CyreneAdmin up to 1.3.0. This affects an unknown part of the file /api/system/us...
CVE-2026-2681MEDIUM5.3A flaw was found in the blst cryptographic library. This out-of-bounds stack write vulnerability, specifically in the bl...
CVE-2026-2504MEDIUM4.3The Dealia – Request a quote plugin for WordPress is vulnerable to unauthorized modification of data due to missing capa...
CVE-2026-2502MEDIUM6.1The xmlrpc attacks blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl...
CVE-2026-2284MEDIUM5.4The News Element Elementor Blog Magazine plugin for WordPress is vulnerable to Missing Authorization in all versions up ...
CVE-2026-2282MEDIUM4.4The Slidorion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to...
CVE-2026-25229MEDIUM6.5Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have a broken access control vulnerability whi...
CVE-2026-1646MEDIUM6.4The Advance Block Extend plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TitleColor block attr...
CVE-2026-1455MEDIUM4.3The Whatsiplus Scheduled Notification for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery i...
CVE-2026-1373MEDIUM6.4The Easy Author Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author_profile_picture_...
CVE-2026-1055MEDIUM4.4The TalkJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, a...
CVE-2026-1047MEDIUM4.4The salavat counter Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'image_url' paramet...
CVE-2026-1044MEDIUM4.4The Tennis Court Bookings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve...
CVE-2026-1043MEDIUM4.4The PostmarkApp Email Integrator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settin...
CVE-2026-0722MEDIUM6.5The Shield Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin...
CVE-2026-0561MEDIUM6.1The Shield Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in ...
CVE-2026-0556MEDIUM6.4The XO Event Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xo_event_field...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now