2026 CVE Vulnerabilities

53,359 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-1401MEDIUM6.4The Tune Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via CSV import in all versions up to,...
CVE-2026-0521MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the PDF export functionality of the TYDAC AG MAP+ solution allow...
CVE-2026-1991MEDIUM5.5A vulnerability was detected in libuvc up to 0.0.7. Affected is the function uvc_scan_streaming of the file src/device.c...
CVE-2026-0598MEDIUM4.2A security flaw was identified in the Ansible Lightspeed API conversation endpoints that handle AI chat interactions. Th...
CVE-2026-1979MEDIUM5.5A flaw has been found in mruby up to 3.4.0. This affects the function mrb_vm_exec of the file src/vm.c of the component ...
CVE-2026-1977MEDIUM6.3A security vulnerability has been detected in isaacwasserman mcp-vegalite-server up to 16aefed598b8cd897b78e99b907f6e298...
CVE-2026-1228MEDIUM4.3The Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) plugin for WordPress is ...
CVE-2026-1971MEDIUM4.8A vulnerability has been found in Edimax BR-6288ACL up to 1.12. Impacted is the function wiz_WISP24gmanual of the file w...
CVE-2026-23623MEDIUM5.3Collabora Online is a collaborative online office suite based on LibreOffice technology. Prior to Collabora Online Devel...
CVE-2026-0391MEDIUM6.5User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attac...
CVE-2026-1970MEDIUM6.1A flaw has been found in Edimax BR-6258n up to 1.18. This issue affects the function formStaDrvSetup of the file /goform...
CVE-2026-1964MEDIUM5.3A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the...
CVE-2026-1301MEDIUM6.8In builds with PubSub and JSON enabled, a crafted JSON message can cause the decoder to write beyond a heap-allocated ar...
CVE-2026-1707MEDIUM6.3pgAdmin versions 9.11 are affected by a Restore restriction bypass via key disclosure vulnerability that occurs when run...
CVE-2026-0715MEDIUM6.8Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provide...
CVE-2026-0714MEDIUM6.8A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption o...
CVE-2026-1927MEDIUM5.4The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to unauthorized access of data due...
CVE-2026-23797MEDIUM4.9In Quick.Cart user passwords are stored in plaintext form. An attacker with high privileges can display users' password ...
CVE-2026-1517MEDIUM4.7A vulnerability was identified in iomad up to 5.0. Affected is an unknown function of the component Company Admin Block....
CVE-2026-1654MEDIUM6.1The Peter's Date Countdown plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_S...
CVE-2026-1271MEDIUM5.3The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Ref...
CVE-2026-1319MEDIUM6.4The Robin Image Optimizer – Unlimited Image Optimization & WebP Converter plugin for WordPress is vulnerable to Stored C...
CVE-2026-25198MEDIUM5.1web2py versions 2.27.1-stable+timestamp.2023.11.16.08.03.57 and prior contain an open redirect vulnerability. If this vu...
CVE-2026-1268MEDIUM6.4The Dynamic Widget Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget content fiel...
CVE-2026-1246MEDIUM4.9The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Arbitrary File Read via path traversal in the 'load...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now