2026 CVE Vulnerabilities
53,401 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1295 | MEDIUM | 6.4 | 0.3% | Jan 28, 2026 | The Buy Now Plus – Buy Now buttons for Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ... |
| CVE-2026-1244 | MEDIUM | 6.4 | 0.3% | Jan 28, 2026 | The Forms Bridge – Infinite integrations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' ... |
| CVE-2026-0825 | MEDIUM | 5.3 | 0.4% | Jan 28, 2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to authorization bypass due... |
| CVE-2026-1298 | MEDIUM | 4.3 | 0.3% | Jan 28, 2026 | The Easy Replace Image plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,... |
| CVE-2026-1083 | MEDIUM | 4.4 | 0.3% | Jan 28, 2026 | The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via fo... |
| CVE-2026-1513 | MEDIUM | 6.1 | 0.2% | Jan 28, 2026 | billboard.js before 3.18.0 allows an attacker to execute malicious JavaScript due to improper sanitization during chart ... |
| CVE-2026-24850 | MEDIUM | 5.3 | 0.3% | Jan 28, 2026 | The ML-DSA crate is a Rust implementation of the Module-Lattice-Based Digital Signature Standard (ML-DSA). Starting in v... |
| CVE-2026-24839 | MEDIUM | 6.1 | 0.2% | Jan 28, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, the Dokploy web interface is... |
| CVE-2026-24838 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2026-24837 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting i... |
| CVE-2026-24836 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting i... |
| CVE-2026-24833 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2026-24784 | MEDIUM | 4.8 | 0.2% | Jan 28, 2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting i... |
| CVE-2026-24134 | MEDIUM | 6.5 | 0.3% | Jan 28, 2026 | StudioCMS is a server-side-rendered, Astro native, headless content management system. Versions prior to 0.2.0 contain a... |
| CVE-2026-24910 | MEDIUM | 5.9 | 0.1% | Jan 27, 2026 | In Bun before 1.3.5, the default trusted dependencies list (aka trust allow list) can be spoofed by a non-npm package in... |
| CVE-2026-24909 | MEDIUM | 5.9 | 0.2% | Jan 27, 2026 | vlt before 1.0.0-rc.10 mishandles path sanitization for tar, leading to path traversal during extraction. |
| CVE-2026-24778 | MEDIUM | 6.1 | 0.3% | Jan 27, 2026 | Ghost is an open source content management system. In Ghost versions 5.43.0 through 5.12.04 and 6.0.0 through 6.14.0, an... |
| CVE-2026-24738 | MEDIUM | 6.5 | 0.3% | Jan 27, 2026 | gmrtd is a Go library for reading Machine Readable Travel Documents (MRTDs). Prior to version 0.17.2, ReadFile accepts T... |
| CVE-2026-1504 | MEDIUM | 6.5 | 0.2% | Jan 27, 2026 | Inappropriate implementation in Background Fetch API in Google Chrome prior to 144.0.7559.110 allowed a remote attacker ... |
| CVE-2026-24771 | MEDIUM | 4.7 | 0.3% | Jan 27, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, a Cross-S... |
| CVE-2026-24688 | MEDIUM | 4.3 | 0.4% | Jan 27, 2026 | pypdf is a free and open-source pure-python PDF library. An attacker who uses an infinite loop vulnerability that is pre... |
| CVE-2026-24473 | MEDIUM | 5.3 | 0.4% | Jan 27, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Serve sta... |
| CVE-2026-24472 | MEDIUM | 5.3 | 0.5% | Jan 27, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Cache Mid... |
| CVE-2026-24883 | MEDIUM | 5.5 | 0.4% | Jan 27, 2026 | In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to ... |
| CVE-2026-24398 | MEDIUM | 6.5 | 0.3% | Jan 27, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, IP Restri... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now