2026 CVE Vulnerabilities

53,226 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-0829MEDIUM5.8The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the s...
CVE-2026-1657MEDIUM5.3The EventPrime plugin for WordPress is vulnerable to unauthorized image file upload in all versions up to, and including...
CVE-2026-2002MEDIUM4.4The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cro...
CVE-2026-2565MEDIUM6.6A weakness has been identified in Wavlink WL-NU516U1 20251208. Affected by this issue is the function sub_40785C of the ...
CVE-2026-2032MEDIUM4.3Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page con...
CVE-2026-2560MEDIUM6.3A vulnerability has been found in kalcaddle kodbox up to 1.64.05. The impacted element is the function run of the file p...
CVE-2026-2558MEDIUM6.3A flaw has been found in GeekAI up to 4.2.4. The affected element is the function Download of the file api/handler/net_h...
CVE-2026-2557MEDIUM5.4A vulnerability was detected in cskefu up to 8.0.1. Impacted is the function Upload of the file com/cskefu/cc/controller...
CVE-2026-2556MEDIUM6.3A security vulnerability has been detected in cskefu up to 8.0.1. This issue affects some unknown processing of the file...
CVE-2026-1046MEDIUM6.5Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost ser...
CVE-2026-2553MEDIUM6.3A security flaw has been discovered in tushar-2223 Hotel-Management-System up to bb1f3b3666124b888f1e4bcf51b6fba9fbb01d1...
CVE-2026-2552MEDIUM5.5A vulnerability was identified in ZenTao up to 21.7.8. Affected by this issue is the function delete of the file editor/...
CVE-2026-2551MEDIUM5.4A vulnerability was determined in ZenTao up to 21.7.8. Affected by this vulnerability is the function delete of the file...
CVE-2026-2452MEDIUM6.5Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used...
CVE-2026-2451MEDIUM6.5Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used...
CVE-2026-2415MEDIUM5.9Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used...
CVE-2026-0999MEDIUM4.3Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate login method restri...
CVE-2026-0998MEDIUM4.3Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 ...
CVE-2026-0997MEDIUM4.3Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 ...
CVE-2026-2548MEDIUM6.3A flaw has been found in WAYOS FBM-220G 24.10.19. This affects the function sub_40F820 of the file rc. Executing a manip...
CVE-2026-2547MEDIUM6.1A vulnerability was detected in LigeroSmart up to 6.1.26. The impacted element is the function AgentDashboard of the fil...
CVE-2026-2546MEDIUM6.1A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of t...
CVE-2026-2545MEDIUM6.1A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?A...
CVE-2026-2543MEDIUM5.1A vulnerability was identified in vichan-devel vichan up to 5.1.5. This vulnerability affects unknown code of the file i...
CVE-2026-0929MEDIUM4.3The RegistrationMagic WordPress plugin before 6.0.7.2 does not have proper capability checks, allowing subscribers and ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now