2026 CVE Vulnerabilities

43,286 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-65325MEDIUM6.3Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the n...
CVE-2026-58156MEDIUM6.3Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affe...
CVE-2026-58152MEDIUM6.9Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. This issue affects Apa...
CVE-2026-11973MEDIUM4.9The WP-Lister Lite for eBay plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in a...
CVE-2026-24033MEDIUM5.3Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic Server....
CVE-2026-22068MEDIUM5.3Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: fr...
CVE-2026-18197MEDIUM6.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allow...
CVE-2026-63242MEDIUM4.3A business logic vulnerability in Koollab LMS allowed an authenticated learner to set their lesson completion status to ...
CVE-2026-63240MEDIUM4.3An information disclosure vulnerability in Koollab LMS allowed an authenticated learner to obtain correct quiz answers f...
CVE-2026-63239MEDIUM5.4A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 bucke...
CVE-2026-63238MEDIUM6.5An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, incl...
CVE-2026-63237MEDIUM4.8A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled s...
CVE-2026-14224MEDIUM5.4The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data...
CVE-2026-13692MEDIUM5.3The PayU CommercePro Plugin WordPress plugin before 3.9.0 does not verify the payment-gateway signature before applying ...
CVE-2026-13605MEDIUM6.8The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox ca...
CVE-2026-11351MEDIUM5.3The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API e...
CVE-2026-5626MEDIUM4.3The Survey Form Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability chec...
CVE-2026-15344MEDIUM4.9The WP Photo Album Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'table' parameter in all ver...
CVE-2026-17166MEDIUM4.3The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress...
CVE-2026-17162MEDIUM6.4The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2026-17161MEDIUM6.4The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2026-15735MEDIUM6.4The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cf7anyapi_form_field'...
CVE-2026-12939MEDIUM6.4The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the p...
CVE-2026-12938MEDIUM6.4The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the...
CVE-2026-66064MEDIUM5.3goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now