2026 CVE Vulnerabilities

53,539 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-22398MEDIUM5.4Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Fleur fleur allows Exploiting Incorrectl...
CVE-2026-22396MEDIUM5.4Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Fiorello fiorello allows Exploiting Inco...
CVE-2026-22393MEDIUM5.4Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Curly curly allows Exploiting Incorrectl...
CVE-2026-22391MEDIUM5.4Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Cocco cocco allows Exploiting Incorrectl...
CVE-2026-22388MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Emu Owl Caro...
CVE-2026-22382MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pa...
CVE-2026-22360MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in AA-Team SearchAzon searchazon allows Cross Site Request Forgery.This ...
CVE-2026-22359MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in AA-Team Wordpress Movies Bulk Importer movies importer allows Cross S...
CVE-2026-22358MEDIUM5.4Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Electrician - Electrical Service WordPress electrician...
CVE-2026-22353MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in winkm89 teachPress...
CVE-2026-22349MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in linux4me2 Menu In ...
CVE-2026-22348MEDIUM5.3Missing Authorization vulnerability in Tasos Fel Civic Cookie Control civic-cookie-control-8 allows Exploiting Incorrect...
CVE-2026-22347MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in subhansanjaya Caro...
CVE-2026-1332MEDIUM6.9MeetingHub developed by HAMASTAR Technology has a Missing Authentication vulnerability, allowing unauthenticated remote ...
CVE-2026-24332MEDIUM4.3Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actual...
CVE-2026-24049MEDIUM5.5wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46...
CVE-2026-24055MEDIUM5.3Langfuse is an open source large language model engineering platform. In versions 3.146.0 and below, the /api/public/sla...
CVE-2026-24039MEDIUM4.3Horilla is a free and open source Human Resource Management System (HRMS). Version 1.4.0 has Improper Access Control, al...
CVE-2026-24037MEDIUM5.4Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the has_xss() function atte...
CVE-2026-24036MEDIUM5.3Horilla is a free and open source Human Resource Management System (HRMS). Versions 1.4.0 and above expose unpublished j...
CVE-2026-24035MEDIUM4.3Horilla is a free and open source Human Resource Management System (HRMS). An Improper Access Control vulnerability exis...
CVE-2026-24034MEDIUM5.4Horilla is a free and open source Human Resource Management System (HRMS). In versions prior to 1.5.0, a cross-site scri...
CVE-2026-23964MEDIUM5.4Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18,...
CVE-2026-23963MEDIUM6.5Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18,...
CVE-2026-23959MEDIUM4.9CoreShop is a Pimcore enhanced eCommerce solution. An error-based SQL Injection vulnerability was identified in versions...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now