2026 CVE Vulnerabilities

53,599 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-22694MEDIUM6.1AliasVault is a privacy-first password manager with built-in email aliasing. AliasVault Android versions 0.24.0 through ...
CVE-2026-22211MEDIUM5.1TinyOS versions up to and including 2.1.2 contain a global buffer overflow vulnerability in the printfUART formatted out...
CVE-2026-22239MEDIUM5.3The vulnerability exists in BLUVOYIX due to design flaws in the email sending API. An unauthenticated remote attacker co...
CVE-2026-0529MEDIUM6.5Improper Validation of Array Index (CWE-129) in Packetbeat’s MongoDB protocol parser can allow an attacker to cause Over...
CVE-2026-0813MEDIUM4.4The Short Link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'short_link_post_title' and 'sh...
CVE-2026-0812MEDIUM4.4The LinkedIn SC plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'linkedin_sc_date_format', 'li...
CVE-2026-0741MEDIUM4.4The Electric Studio Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin se...
CVE-2026-0739MEDIUM4.4The WMF Mobile Redirector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in a...
CVE-2026-0734MEDIUM4.4The WP Allowed Hosts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'allowed-hosts' parameter...
CVE-2026-0717MEDIUM5.3The LottieFiles – Lottie block for Gutenberg plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
CVE-2026-0694MEDIUM6.4The SearchWiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in search results in all...
CVE-2026-0680MEDIUM4.4The Real Post Slider Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in a...
CVE-2026-0678MEDIUM4.9The Flat Shipping Rate by City for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the 'c...
CVE-2026-0635MEDIUM4.3The Responsive Accordion Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...
CVE-2026-0594MEDIUM6.1The List Site Contributors plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'alpha' paramete...
CVE-2026-22718MEDIUM6.8The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users mac...
CVE-2026-0716MEDIUM4.8A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration...
CVE-2026-21303MEDIUM5.5Substance3D - Modeler versions 1.22.4 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to...
CVE-2026-21302MEDIUM5.5Substance3D - Modeler versions 1.22.4 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to...
CVE-2026-21301MEDIUM5.5Substance3D - Modeler versions 1.22.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could le...
CVE-2026-21300MEDIUM5.5Substance3D - Modeler versions 1.22.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could le...
CVE-2026-0543MEDIUM6.5Improper Input Validation (CWE-20) in Kibana's Email Connector can allow an attacker to cause an Excessive Allocation (C...
CVE-2026-0531MEDIUM6.5Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-1...
CVE-2026-0530MEDIUM6.5Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-1...
CVE-2026-22818MEDIUM6.5Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw i...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now