2026 CVE Vulnerabilities

53,393 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-24961MEDIUM5.4Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Grand Blog grandblog allows Server Side Request Forgery.T...
CVE-2026-24958MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElem...
CVE-2026-24957MEDIUM6.5Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Exploiting Incorrectly Co...
CVE-2026-24952MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Serio...
CVE-2026-24951MEDIUM4.3Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control ...
CVE-2026-24947MEDIUM4.3Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Exploit...
CVE-2026-24945MEDIUM5.3Missing Authorization vulnerability in Themefic Ultimate Addons for Contact Form 7 ultimate-addons-for-contact-form-7 al...
CVE-2026-24942MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in magepeopleteam WpEvently mage-eventpress allows Cross Site Request Fo...
CVE-2026-24940MEDIUM4.3Missing Authorization vulnerability in Themefic Travelfic Toolkit travelfic-toolkit allows Exploiting Incorrectly Config...
CVE-2026-24939MEDIUM4.3Missing Authorization vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Exploiting Incorrec...
CVE-2026-24938MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Better Search...
CVE-2026-1814MEDIUM6.8Rapid7 Nexpose versions 6.4.50 and later are vulnerable to an insufficient entropy issue in the CredentialsKeyStorePassw...
CVE-2026-1312MEDIUM5.4An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject...
CVE-2026-1287MEDIUM5.4An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to ...
CVE-2026-1207MEDIUM5.4An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField``...
CVE-2026-1664MEDIUM6.9Summary An Insecure Direct Object Reference has been found to exist in `createHeaderBasedEmailResolver()` function with...
CVE-2026-1592MEDIUM5.4Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the Create New Layer feature....
CVE-2026-1591MEDIUM5.4Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the file upload feature. A ma...
CVE-2026-1371MEDIUM5.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposur...
CVE-2026-24449MEDIUM5.1For WRC-X1500GS-B and WRC-X1500GSA-B, the initial passwords can be calculated easily from the system information.
CVE-2026-20704MEDIUM5.1Cross-site request forgery vulnerability exists in ELECOM wireless LAN products. If a user accesses a malicious page whi...
CVE-2026-1447MEDIUM5.4The Mail Mint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1...
CVE-2026-1210MEDIUM6.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_elementor_dat...
CVE-2026-0950MEDIUM5.3The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Information Di...
CVE-2026-1788MEDIUM6.6: Out-of-bounds Write vulnerability in Xquic Project Xquic Server xquic on Linux (QUIC protocol implementation, packet p...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now