2026 CVE Vulnerabilities

53,212 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-1304MEDIUM4.4The Membership Plugin – Restrict Content for WordPress is vulnerable to Stored Cross-Site Scripting via multiple invoice...
CVE-2026-1072MEDIUM4.3The Keybase.io Verification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2026-1925MEDIUM4.3The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to unauthorized data modificatio...
CVE-2026-1296MEDIUM6.1The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Open Redirection in all versions up to, ...
CVE-2026-1277MEDIUM4.7The URL Shortify plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.12.1 due to...
CVE-2026-27171MEDIUM5.5zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts...
CVE-2026-1344MEDIUM5.5Tanium addressed an insecure file permissions vulnerability in Enforce Recovery Key Portal.
CVE-2026-2622MEDIUM5.4A vulnerability was detected in Blossom up to 1.17.1. This vulnerability affects the function content of the file blosso...
CVE-2026-23598MEDIUM6.5Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated ...
CVE-2026-23597MEDIUM6.5Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated ...
CVE-2026-23596MEDIUM6.5A vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger ...
CVE-2026-26357MEDIUM5.4Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Input During Web Page Generati...
CVE-2026-22762MEDIUM6.5Dell Avamar Server and Avamar Virtual Edition, versions prior to 19.10 SP1 with CHF338912, contain an Improper Limitatio...
CVE-2026-23861MEDIUM5.4Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Input During Web Page Gen...
CVE-2026-2608MEDIUM4.3The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access...
CVE-2026-25903MEDIUM6.6Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components...
CVE-2026-0829MEDIUM5.8The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the s...
CVE-2026-1657MEDIUM5.3The EventPrime plugin for WordPress is vulnerable to unauthorized image file upload in all versions up to, and including...
CVE-2026-2002MEDIUM4.4The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cro...
CVE-2026-2565MEDIUM6.6A weakness has been identified in Wavlink WL-NU516U1 20251208. Affected by this issue is the function sub_40785C of the ...
CVE-2026-2032MEDIUM4.3Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page con...
CVE-2026-2560MEDIUM6.3A vulnerability has been found in kalcaddle kodbox up to 1.64.05. The impacted element is the function run of the file p...
CVE-2026-2558MEDIUM6.3A flaw has been found in GeekAI up to 4.2.4. The affected element is the function Download of the file api/handler/net_h...
CVE-2026-2557MEDIUM5.4A vulnerability was detected in cskefu up to 8.0.1. Impacted is the function Upload of the file com/cskefu/cc/controller...
CVE-2026-2556MEDIUM6.3A security vulnerability has been detected in cskefu up to 8.0.1. This issue affects some unknown processing of the file...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now