2026 CVE Vulnerabilities

53,582 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-1004MEDIUM5.3The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ...
CVE-2026-0913MEDIUM6.4The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored ...
CVE-2026-1003MEDIUM4.3The GetGenie plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.3.0. Thi...
CVE-2026-0942MEDIUM5.3The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit plugin for WordPress is vulnerable to unauthorized mo...
CVE-2026-0939MEDIUM5.3The Rede Itaú for WooCommerce plugin for WordPress is vulnerable to order status manipulation due to insufficient verifi...
CVE-2026-0916MEDIUM6.4The Related Posts by Taxonomy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'relate...
CVE-2026-23769MEDIUM6.1lucy-xss-filter before commit e5826c0 allows an attacker to execute malicious JavaScript due to improper sanitization ca...
CVE-2026-23768MEDIUM6.1lucy-xss-filter before commit 7c1de6d allows an attacker to induce server-side HEAD requests to arbitrary URLs when the ...
CVE-2026-1000MEDIUM6.5The MailerLite - WooCommerce integration plugin for WordPress is vulnerable to unauthorized data modification and deleti...
CVE-2026-0858MEDIUM6.1Versions of the package net.sourceforge.plantuml:plantuml before 1.2026.0 are vulnerable to Stored XSS due to insufficie...
CVE-2026-1011MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in the Altium Support Center AddComment endpoint due to missing...
CVE-2026-1010MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in the Altium Workflow Engine due to missing server-side input ...
CVE-2026-1009MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitizati...
CVE-2026-1008MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in the user profile text fields of Altium 365. Insufficient ser...
CVE-2026-21912MEDIUM4.7A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the method to collect FPC Ethernet firmware statist...
CVE-2026-1002MEDIUM5.3The Vert.x Web static handler component cache can be manipulated to deny the access to static files served by the handle...
CVE-2026-23511MEDIUM5.3ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has b...
CVE-2026-23496MEDIUM5.4Pimcore Web2Print Tools Bundle adds tools for web-to-print use cases to Pimcore. Prior to 5.2.2 and 6.1.1, the applicati...
CVE-2026-23495MEDIUM4.3Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Prior to 2.2.3 and 1.7.16, the API endpoint for listin...
CVE-2026-23494MEDIUM6.5Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the application fails to e...
CVE-2026-23493MEDIUM4.9Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the http_error_log file st...
CVE-2026-22867MEDIUM5.4LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 3.8.0 to 4.3.0, a Stored Cross-Site Sc...
CVE-2026-20076MEDIUM4.8A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2026-20075MEDIUM4.8A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri...
CVE-2026-20047MEDIUM4.8A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Iden...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now