2026 CVE Vulnerabilities

53,516 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-24522MEDIUM4.3Missing Authorization vulnerability in MyThemeShop WP Subscribe wp-subscribe allows Exploiting Incorrectly Configured Ac...
CVE-2026-24521MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Timur Kamaev Kama Thumbnail kama-thumbnail allows Cross Site Request ...
CVE-2026-0914MEDIUM6.4The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lw_content...
CVE-2026-22276MEDIUM5.5Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Storage...
CVE-2026-22275MEDIUM4.4Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Inclusion of Sen...
CVE-2026-22274MEDIUM6.5Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmi...
CVE-2026-0927MEDIUM5.3The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to arbitrary file uploads due...
CVE-2026-0788MEDIUM6.1ALGO 8180 IP Audio Alerter Web UI Persistent Cross-Site Scripting Vulnerability. This vulnerability allows remote attack...
CVE-2026-24137MEDIUM5.8sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the...
CVE-2026-24130MEDIUM5.3Moonraker is a Python web server providing API access to Klipper 3D printing firmware. In versions 0.9.3 and below, inst...
CVE-2026-21264MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unau...
CVE-2026-24117MEDIUM5.3Rekor is a software supply chain transparency log. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary ...
CVE-2026-23831MEDIUM5.3Rekor is a software supply chain transparency log. In versions 1.4.3 and below, the entry implementation can panic on at...
CVE-2026-20904MEDIUM6.5Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to cha...
CVE-2026-20888MEDIUM4.3Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with rea...
CVE-2026-20883MEDIUM6.5Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository ...
CVE-2026-20800MEDIUM6.5Gitea's notification API does not re-validate repository access permissions when returning notification details. After a...
CVE-2026-22281MEDIUM4.8Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.1...
CVE-2026-22280MEDIUM5.5Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.1...
CVE-2026-24389MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Gallery P...
CVE-2026-24388MEDIUM4.3Missing Authorization vulnerability in Ludwig You WPMasterToolKit wpmastertoolkit allows Exploiting Incorrectly Configur...
CVE-2026-24387MEDIUM4.3Missing Authorization vulnerability in Arul Prasad J WP Quick Post Duplicator wp-quick-post-duplicator allows Exploiting...
CVE-2026-24386MEDIUM4.3Missing Authorization vulnerability in Element Invader Element Invader – Template Kits for Elementor elementinvader allo...
CVE-2026-24384MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in launchinteractive Merge + Minify + Refresh merge-minify-refresh allow...
CVE-2026-24383MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Slider ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now