2026 CVE Vulnerabilities

53,401 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-24768MEDIUM6.1NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, an unvalidated redirect (open redir...
CVE-2026-24767MEDIUM6.4NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a blind Server-Side Request Forgery...
CVE-2026-24766MEDIUM4.9NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, an authenticated user with org-leve...
CVE-2026-24742MEDIUM6.5Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-adm...
CVE-2026-24739MEDIUM6.3Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to versions 5.4....
CVE-2026-1532MEDIUM5.5A vulnerability was identified in D-Link DCS-700L 1.03.09. The affected element is the function uploadmusic of the file ...
CVE-2026-21865MEDIUM6.5Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderat...
CVE-2026-0749MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Form Builde...
CVE-2026-1539MEDIUM5.8A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended de...
CVE-2026-1536MEDIUM5.3A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (C...
CVE-2026-23014MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: perf: Ensure swevent hrtimer is properly destroyed ...
CVE-2026-1060MEDIUM5.3The WP Adminify plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin...
CVE-2026-1399MEDIUM4.4The WP Google Ad Manager Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ...
CVE-2026-1398MEDIUM4.3The Change WP URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2026-1391MEDIUM5.3The Vzaar Media Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a...
CVE-2026-1380MEDIUM4.3The Bitcoin Donate Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2026-1377MEDIUM4.3The imwptip plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. ...
CVE-2026-0483MEDIUM6.9Stored Cross-Site Scripting (XSS) vulnerability in the PDF file upload functionality of Live Helper Chat, versions prior...
CVE-2026-1381MEDIUM4.4The Order Minimum/Maximum Amount Limits for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2026-1053MEDIUM4.4The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin s...
CVE-2026-1389MEDIUM4.3The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to Insecure Direct O...
CVE-2026-1054MEDIUM5.3The RegistrationMagic plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.0....
CVE-2026-0818MEDIUM4.3When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of...
CVE-2026-1466MEDIUM6.1Jirafeau normally prevents browser preview for text files due to the possibility that for example SVG and HTML documents...
CVE-2026-1310MEDIUM5.3The Simple calendar for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now