2026 CVE Vulnerabilities

53,401 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-1295MEDIUM6.4The Buy Now Plus – Buy Now buttons for Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
CVE-2026-1244MEDIUM6.4The Forms Bridge – Infinite integrations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' ...
CVE-2026-0825MEDIUM5.3The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to authorization bypass due...
CVE-2026-1298MEDIUM4.3The Easy Replace Image plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,...
CVE-2026-1083MEDIUM4.4The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via fo...
CVE-2026-1513MEDIUM6.1billboard.js before 3.18.0 allows an attacker to execute malicious JavaScript due to improper sanitization during chart ...
CVE-2026-24850MEDIUM5.3The ML-DSA crate is a Rust implementation of the Module-Lattice-Based Digital Signature Standard (ML-DSA). Starting in v...
CVE-2026-24839MEDIUM6.1Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, the Dokploy web interface is...
CVE-2026-24838MEDIUM5.4DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2026-24837MEDIUM5.4DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting i...
CVE-2026-24836MEDIUM5.4DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting i...
CVE-2026-24833MEDIUM5.4DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2026-24784MEDIUM4.8DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting i...
CVE-2026-24134MEDIUM6.5StudioCMS is a server-side-rendered, Astro native, headless content management system. Versions prior to 0.2.0 contain a...
CVE-2026-24910MEDIUM5.9In Bun before 1.3.5, the default trusted dependencies list (aka trust allow list) can be spoofed by a non-npm package in...
CVE-2026-24909MEDIUM5.9vlt before 1.0.0-rc.10 mishandles path sanitization for tar, leading to path traversal during extraction.
CVE-2026-24778MEDIUM6.1Ghost is an open source content management system. In Ghost versions 5.43.0 through 5.12.04 and 6.0.0 through 6.14.0, an...
CVE-2026-24738MEDIUM6.5gmrtd is a Go library for reading Machine Readable Travel Documents (MRTDs). Prior to version 0.17.2, ReadFile accepts T...
CVE-2026-1504MEDIUM6.5Inappropriate implementation in Background Fetch API in Google Chrome prior to 144.0.7559.110 allowed a remote attacker ...
CVE-2026-24771MEDIUM4.7Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, a Cross-S...
CVE-2026-24688MEDIUM4.3pypdf is a free and open-source pure-python PDF library. An attacker who uses an infinite loop vulnerability that is pre...
CVE-2026-24473MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Serve sta...
CVE-2026-24472MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Cache Mid...
CVE-2026-24883MEDIUM5.5In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to ...
CVE-2026-24398MEDIUM6.5Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, IP Restri...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now