2026 CVE Vulnerabilities

53,579 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-0808MEDIUM5.3The Spin Wheel plugin for WordPress is vulnerable to client-side prize manipulation in all versions up to, and including...
CVE-2026-0691MEDIUM4.4The CM E-Mail Blacklist – Simple email filtering for safer registration plugin for WordPress is vulnerable to Stored Cro...
CVE-2026-0820MEDIUM4.3The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct O...
CVE-2026-0518MEDIUM4.8CVE-2026-0518 is a cross-site scripting vulnerability in versions of Secure Access prior to 14.20. An attacker with adm...
CVE-2026-23745MEDIUM6.1node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and Sym...
CVE-2026-23643MEDIUM5.4CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting ...
CVE-2026-23731MEDIUM4.3WeGIA is a web manager for charitable institutions. Prior to 3.6.2, The web application is vulnerable to clickjacking at...
CVE-2026-23730MEDIUM6.1WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the...
CVE-2026-23729MEDIUM6.1WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the...
CVE-2026-23728MEDIUM6.1WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the...
CVE-2026-23727MEDIUM6.1WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the...
CVE-2026-23726MEDIUM6.1WeGIA is a web manager for charitable institutions. Prior to 3.6.2, An Open Redirect vulnerability was identified in the...
CVE-2026-23725MEDIUM5.4WeGIA is a web manager for charitable institutions. Prior to 3.6.2, a Stored Cross-Site Scripting (XSS) vulnerability wa...
CVE-2026-23724MEDIUM5.4WeGIA is a web manager for charitable institutions. Prior to 3.6.2, a Stored Cross-Site Scripting (XSS) vulnerability wa...
CVE-2026-23722MEDIUM6.1WeGIA is a Web Manager for Charitable Institutions. Prior to 3.6.2, a Reflected Cross-Site Scripting (XSS) vulnerability...
CVE-2026-23645MEDIUM6.1SiYuan is self-hosted, open source personal knowledge management software. Prior to 3.5.4-dev2, a Stored Cross-Site Scri...
CVE-2026-23634MEDIUM4.3Pepr is a type safe K8s middleware. Prior to 1.0.5 , Pepr defaults to a cluster-admin RBAC configuration and does not ex...
CVE-2026-23528MEDIUM6.1Dask distributed is a distributed task scheduler for Dask. Prior to 2026.1.0, when Jupyter Lab, jupyter-server-proxy, an...
CVE-2026-0949MEDIUM4.8PEM versions prior to 9.8.1 are affected by a stored Cross-site Scripting (XSS) vulnerability that allows users with acc...
CVE-2026-21624MEDIUM5.4Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss com...
CVE-2026-21623MEDIUM5.4Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component...
CVE-2026-0696MEDIUM6.5In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some...
CVE-2026-0695MEDIUM5.4In ConnectWise PSA versions older than 2026.1, Time Entry notes stored in the Time Entry Audit Trail may be rendered wit...
CVE-2026-20894MEDIUM4.8Cross-site scripting vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation. If a...
CVE-2026-1004MEDIUM5.3The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now