2026 CVE Vulnerabilities

53,356 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-25566MEDIUM5.4WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination...
CVE-2026-25565MEDIUM6.5WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only bo...
CVE-2026-25562MEDIUM4.3WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment ...
CVE-2026-2111MEDIUM4.3A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this issue is some unknown functionality of the fil...
CVE-2026-1675MEDIUM5.3The Advanced Country Blocker plugin for WordPress is vulnerable to Authorization Bypass in all versions up to, and inclu...
CVE-2026-1643MEDIUM6.1The MP-Ukagaka plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including...
CVE-2026-1634MEDIUM6.1The Subitem AL Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']...
CVE-2026-1613MEDIUM6.4The Wonka Slide plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `list_class` shortcod...
CVE-2026-1611MEDIUM6.4The Wikiloops Track Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wikiloops...
CVE-2026-1608MEDIUM6.4The Video Onclick plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `youtube` shortcode...
CVE-2026-1573MEDIUM6.4The OMIGO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `omigo_donate_button` short...
CVE-2026-1570MEDIUM6.4The Simple Bible Verse via Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
CVE-2026-1082MEDIUM4.3The TITLE ANIMATOR plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2026-0555MEDIUM6.4The Premmerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premmerce_wizard_actions' AJAX ...
CVE-2026-2074MEDIUM6.3A vulnerability was identified in O2OA up to 9.0.0. This impacts an unknown function of the file /x_program_center/jaxrs...
CVE-2026-25757MEDIUM5.3Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2,...
CVE-2026-25749MEDIUM6.6Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists ...
CVE-2026-25760MEDIUM6.5Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.6.11, a path traversal in th...
CVE-2026-25574MEDIUM5.4Payload is a free and open source headless content management system. Prior to 3.74.0, a cross-collection Insecure Direc...
CVE-2026-25516MEDIUM6.1NiceGUI is a Python-based UI framework. The ui.markdown() component uses the markdown2 library to convert markdown conte...
CVE-2026-25123MEDIUM5.3Homarr is an open-source dashboard. Prior to 1.52.0, a public (unauthenticated) tRPC endpoint widget.app.ping accepts an...
CVE-2026-25729MEDIUM6.5DeepAudit is a multi-agent system for code vulnerability discovery. In 3.0.4 and earlier, there is an improper access co...
CVE-2026-25631MEDIUM6.5n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node'...
CVE-2026-25597MEDIUM5.3PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeratio...
CVE-2026-25581MEDIUM5.4SCEditor is a lightweight WYSIWYG BBCode and XHTML editor. Prior to 3.2.1, if an attacker has the ability control config...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now