2026 CVE Vulnerabilities
53,516 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24522 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in MyThemeShop WP Subscribe wp-subscribe allows Exploiting Incorrectly Configured Ac... |
| CVE-2026-24521 | MEDIUM | 4.3 | 0.1% | Jan 23, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Timur Kamaev Kama Thumbnail kama-thumbnail allows Cross Site Request ... |
| CVE-2026-0914 | MEDIUM | 6.4 | 0.3% | Jan 23, 2026 | The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lw_content... |
| CVE-2026-22276 | MEDIUM | 5.5 | 0.1% | Jan 23, 2026 | Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Storage... |
| CVE-2026-22275 | MEDIUM | 4.4 | 0.1% | Jan 23, 2026 | Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Inclusion of Sen... |
| CVE-2026-22274 | MEDIUM | 6.5 | 0.2% | Jan 23, 2026 | Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmi... |
| CVE-2026-0927 | MEDIUM | 5.3 | 0.3% | Jan 23, 2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to arbitrary file uploads due... |
| CVE-2026-0788 | MEDIUM | 6.1 | 0.4% | Jan 23, 2026 | ALGO 8180 IP Audio Alerter Web UI Persistent Cross-Site Scripting Vulnerability. This vulnerability allows remote attack... |
| CVE-2026-24137 | MEDIUM | 5.8 | 0.4% | Jan 23, 2026 | sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the... |
| CVE-2026-24130 | MEDIUM | 5.3 | 0.3% | Jan 22, 2026 | Moonraker is a Python web server providing API access to Klipper 3D printing firmware. In versions 0.9.3 and below, inst... |
| CVE-2026-21264 | MEDIUM | 6.1 | 0.4% | Jan 22, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unau... |
| CVE-2026-24117 | MEDIUM | 5.3 | 0.3% | Jan 22, 2026 | Rekor is a software supply chain transparency log. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary ... |
| CVE-2026-23831 | MEDIUM | 5.3 | 0.4% | Jan 22, 2026 | Rekor is a software supply chain transparency log. In versions 1.4.3 and below, the entry implementation can panic on at... |
| CVE-2026-20904 | MEDIUM | 6.5 | 0.3% | Jan 22, 2026 | Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to cha... |
| CVE-2026-20888 | MEDIUM | 4.3 | 0.3% | Jan 22, 2026 | Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with rea... |
| CVE-2026-20883 | MEDIUM | 6.5 | 0.3% | Jan 22, 2026 | Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository ... |
| CVE-2026-20800 | MEDIUM | 6.5 | 0.3% | Jan 22, 2026 | Gitea's notification API does not re-validate repository access permissions when returning notification details. After a... |
| CVE-2026-22281 | MEDIUM | 4.8 | 0.2% | Jan 22, 2026 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.1... |
| CVE-2026-22280 | MEDIUM | 5.5 | 0.1% | Jan 22, 2026 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.1... |
| CVE-2026-24389 | MEDIUM | 6.5 | 0.1% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Gallery P... |
| CVE-2026-24388 | MEDIUM | 4.3 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in Ludwig You WPMasterToolKit wpmastertoolkit allows Exploiting Incorrectly Configur... |
| CVE-2026-24387 | MEDIUM | 4.3 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in Arul Prasad J WP Quick Post Duplicator wp-quick-post-duplicator allows Exploiting... |
| CVE-2026-24386 | MEDIUM | 4.3 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in Element Invader Element Invader – Template Kits for Elementor elementinvader allo... |
| CVE-2026-24384 | MEDIUM | 5.4 | 0.1% | Jan 22, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in launchinteractive Merge + Minify + Refresh merge-minify-refresh allow... |
| CVE-2026-24383 | MEDIUM | 6.5 | 0.1% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Slider ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now