2026 CVE Vulnerabilities

53,398 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-1447MEDIUM5.4The Mail Mint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1...
CVE-2026-1210MEDIUM6.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_elementor_dat...
CVE-2026-0950MEDIUM5.3The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Information Di...
CVE-2026-1788MEDIUM6.6: Out-of-bounds Write vulnerability in Xquic Project Xquic Server xquic on Linux (QUIC protocol implementation, packet p...
CVE-2026-0909MEDIUM5.3The WP ULike plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including...
CVE-2026-24935MEDIUM5.6A third-party NAT traversal module fails to validate SSL/TLS certificates when connecting to the signaling server. While...
CVE-2026-24933MEDIUM5.9The API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An ...
CVE-2026-24932MEDIUM5.9The DDNS update function in ADM fails to properly validate the hostname of the DDNS server's TLS/SSL certificate. Althou...
CVE-2026-25228MEDIUM4.3Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.20.3, a path traversal vulnerab...
CVE-2026-25144MEDIUM5.3Talishar is a fan-made Flesh and Blood project. A Stored XSS exists in the chat in-game system. The playerID parameter i...
CVE-2026-24133MEDIUM6.5jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argument of the addImage me...
CVE-2026-24043MEDIUM5.4jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argument of the addMetadata...
CVE-2026-24040MEDIUM4.8jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, the addJS method in the jspdf Node.js build utilizes ...
CVE-2026-24007MEDIUM4.6Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap is missing CSRF protecti...
CVE-2026-23476MEDIUM5.4FacturaScripts is open-source enterprise resource planning and accounting software. Prior to 2025.8, there a reflected X...
CVE-2026-22780MEDIUM6.1Rizin is a UNIX-like reverse engineering framework and command-line toolset. Prior to 0.8.2, a heap overflow can be expl...
CVE-2026-1770MEDIUM4.5Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticat...
CVE-2026-1232MEDIUM6.8A medium-severity vulnerability has been identified in BeyondTrust Privilege Management for Windows versions <=25.7. Und...
CVE-2026-1760MEDIUM5.3A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs because SoupServer improperly handles r...
CVE-2026-1757MEDIUM6.2A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocat...
CVE-2026-20422MEDIUM6.5In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service...
CVE-2026-20421MEDIUM6.5In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service...
CVE-2026-20420MEDIUM6.5In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,...
CVE-2026-20419MEDIUM6.5In wlan AP/STA firmware, there is a possible system becoming irresponsive due to an uncaught exception. This could lead ...
CVE-2026-20417MEDIUM5.3In pcie, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now