2026 CVE Vulnerabilities

53,500 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-24542MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in John James Jacoby WP Term Order wp-term-order allows Cross Site Reque...
CVE-2026-24541MEDIUM4.3Missing Authorization vulnerability in mkscripts Download After Email download-after-email allows Exploiting Incorrectly...
CVE-2026-24540MEDIUM5.4Missing Authorization vulnerability in princeahmed Integrate Google Drive integrate-google-drive allows Exploiting Incor...
CVE-2026-24539MEDIUM5.3Missing Authorization vulnerability in ABCdatos Protección de datos – RGPD proteccion-datos-rgpd allows Exploiting Incor...
CVE-2026-24536MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in webpushr Webpushr webpushr-w...
CVE-2026-24535MEDIUM4.3Missing Authorization vulnerability in webdevstudios Automatic Featured Images from Videos automatic-featured-images-fro...
CVE-2026-24534MEDIUM4.3Missing Authorization vulnerability in uPress Booter booter-bots-crawlers-manager allows Exploiting Incorrectly Configur...
CVE-2026-24532MEDIUM4.3Missing Authorization vulnerability in SiteLock SiteLock Security – WP Hardening, Login Security & Malware Scans siteloc...
CVE-2026-24530MEDIUM5.3Missing Authorization vulnerability in sheepfish WebP Conversion webp-conversion allows Exploiting Incorrectly Configure...
CVE-2026-24529MEDIUM5.3Missing Authorization vulnerability in Alejandro Quick Restaurant Reservations quick-restaurant-reservations allows Expl...
CVE-2026-24528MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixelgrade Nova Bl...
CVE-2026-24526MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Steve Truman Email...
CVE-2026-24525MEDIUM5.3Missing Authorization vulnerability in CloudPanel CLP Varnish Cache clp-varnish-cache allows Exploiting Incorrectly Conf...
CVE-2026-24524MEDIUM4.3Missing Authorization vulnerability in Essekia Tablesome tablesome allows Exploiting Incorrectly Configured Access Contr...
CVE-2026-24523MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Marcus (aka @msykes) WP Full...
CVE-2026-24522MEDIUM4.3Missing Authorization vulnerability in MyThemeShop WP Subscribe wp-subscribe allows Exploiting Incorrectly Configured Ac...
CVE-2026-24521MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Timur Kamaev Kama Thumbnail kama-thumbnail allows Cross Site Request ...
CVE-2026-0914MEDIUM6.4The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lw_content...
CVE-2026-22276MEDIUM5.5Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Storage...
CVE-2026-22275MEDIUM4.4Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Inclusion of Sen...
CVE-2026-22274MEDIUM6.5Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmi...
CVE-2026-0927MEDIUM5.3The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to arbitrary file uploads due...
CVE-2026-0788MEDIUM6.1ALGO 8180 IP Audio Alerter Web UI Persistent Cross-Site Scripting Vulnerability. This vulnerability allows remote attack...
CVE-2026-24137MEDIUM5.8sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the...
CVE-2026-24130MEDIUM5.3Moonraker is a Python web server providing API access to Klipper 3D printing firmware. In versions 0.9.3 and below, inst...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now