2026 CVE Vulnerabilities
53,579 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0808 | MEDIUM | 5.3 | 0.3% | Jan 17, 2026 | The Spin Wheel plugin for WordPress is vulnerable to client-side prize manipulation in all versions up to, and including... |
| CVE-2026-0691 | MEDIUM | 4.4 | 0.3% | Jan 17, 2026 | The CM E-Mail Blacklist – Simple email filtering for safer registration plugin for WordPress is vulnerable to Stored Cro... |
| CVE-2026-0820 | MEDIUM | 4.3 | 0.2% | Jan 17, 2026 | The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct O... |
| CVE-2026-0518 | MEDIUM | 4.8 | 0.1% | Jan 17, 2026 | CVE-2026-0518 is a cross-site scripting vulnerability in versions of Secure Access prior to 14.20. An attacker with adm... |
| CVE-2026-23745 | MEDIUM | 6.1 | 0.3% | Jan 16, 2026 | node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and Sym... |
| CVE-2026-23643 | MEDIUM | 5.4 | 0.3% | Jan 16, 2026 | CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting ... |
| CVE-2026-23731 | MEDIUM | 4.3 | 0.3% | Jan 16, 2026 | WeGIA is a web manager for charitable institutions. Prior to 3.6.2, The web application is vulnerable to clickjacking at... |
| CVE-2026-23730 | MEDIUM | 6.1 | 0.2% | Jan 16, 2026 | WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the... |
| CVE-2026-23729 | MEDIUM | 6.1 | 0.2% | Jan 16, 2026 | WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the... |
| CVE-2026-23728 | MEDIUM | 6.1 | 0.2% | Jan 16, 2026 | WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the... |
| CVE-2026-23727 | MEDIUM | 6.1 | 0.2% | Jan 16, 2026 | WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the... |
| CVE-2026-23726 | MEDIUM | 6.1 | 0.2% | Jan 16, 2026 | WeGIA is a web manager for charitable institutions. Prior to 3.6.2, An Open Redirect vulnerability was identified in the... |
| CVE-2026-23725 | MEDIUM | 5.4 | 0.2% | Jan 16, 2026 | WeGIA is a web manager for charitable institutions. Prior to 3.6.2, a Stored Cross-Site Scripting (XSS) vulnerability wa... |
| CVE-2026-23724 | MEDIUM | 5.4 | 0.2% | Jan 16, 2026 | WeGIA is a web manager for charitable institutions. Prior to 3.6.2, a Stored Cross-Site Scripting (XSS) vulnerability wa... |
| CVE-2026-23722 | MEDIUM | 6.1 | 0.2% | Jan 16, 2026 | WeGIA is a Web Manager for Charitable Institutions. Prior to 3.6.2, a Reflected Cross-Site Scripting (XSS) vulnerability... |
| CVE-2026-23645 | MEDIUM | 6.1 | 0.3% | Jan 16, 2026 | SiYuan is self-hosted, open source personal knowledge management software. Prior to 3.5.4-dev2, a Stored Cross-Site Scri... |
| CVE-2026-23634 | MEDIUM | 4.3 | 0.2% | Jan 16, 2026 | Pepr is a type safe K8s middleware. Prior to 1.0.5 , Pepr defaults to a cluster-admin RBAC configuration and does not ex... |
| CVE-2026-23528 | MEDIUM | 6.1 | 0.2% | Jan 16, 2026 | Dask distributed is a distributed task scheduler for Dask. Prior to 2026.1.0, when Jupyter Lab, jupyter-server-proxy, an... |
| CVE-2026-0949 | MEDIUM | 4.8 | 0.2% | Jan 16, 2026 | PEM versions prior to 9.8.1 are affected by a stored Cross-site Scripting (XSS) vulnerability that allows users with acc... |
| CVE-2026-21624 | MEDIUM | 5.4 | 0.2% | Jan 16, 2026 | Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss com... |
| CVE-2026-21623 | MEDIUM | 5.4 | 0.2% | Jan 16, 2026 | Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component... |
| CVE-2026-0696 | MEDIUM | 6.5 | 0.4% | Jan 16, 2026 | In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some... |
| CVE-2026-0695 | MEDIUM | 5.4 | 0.3% | Jan 16, 2026 | In ConnectWise PSA versions older than 2026.1, Time Entry notes stored in the Time Entry Audit Trail may be rendered wit... |
| CVE-2026-20894 | MEDIUM | 4.8 | 0.2% | Jan 16, 2026 | Cross-site scripting vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation. If a... |
| CVE-2026-1004 | MEDIUM | 5.3 | 0.3% | Jan 16, 2026 | The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now