2026 CVE Vulnerabilities

43,286 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-62423MEDIUM5.5[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-42495MEDIUM5.5[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-42494MEDIUM6.1[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-41874MEDIUM6.8Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with acces...
CVE-2026-18047MEDIUM6.5A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching fo...
CVE-2026-18038MEDIUM4.3A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function ExecTool.E...
CVE-2026-15393MEDIUM6.4The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress...
CVE-2026-15016MEDIUM6.4The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerab...
CVE-2026-4648MEDIUM6.8Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from CasfID Servicios Tec...
CVE-2026-16774MEDIUM5.3The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the ...
CVE-2026-16773MEDIUM5.3The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive In...
CVE-2026-15444MEDIUM4.9The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the...
CVE-2026-15411MEDIUM5.3The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for ...
CVE-2026-13110MEDIUM5.3The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and includin...
CVE-2026-63303MEDIUM5.1A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fai...
CVE-2026-63302MEDIUM5.1Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated at...
CVE-2026-18029MEDIUM6.3Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a s...
CVE-2026-65624MEDIUM6.9Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote ...
CVE-2026-58246MEDIUM4.3SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagn...
CVE-2026-11598MEDIUM5The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'name' Shortcode Attribute in all ...
CVE-2026-9680MEDIUM5.8Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP...
CVE-2026-8167MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solu...
CVE-2026-44387MEDIUM5.2ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. I...
CVE-2026-15267MEDIUM6.5The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL ...
CVE-2026-14171MEDIUM6.1An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now