2026 CVE Vulnerabilities

43,297 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-59560MEDIUM6.5Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.
CVE-2026-59559MEDIUM6.5Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 version...
CVE-2026-59557MEDIUM6.5Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
CVE-2026-10819MEDIUM6.5Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number o...
CVE-2026-10600MEDIUM4.3Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and...
CVE-2026-17514MEDIUM5.3A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Ex...
CVE-2026-15003MEDIUM5.6A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125...
CVE-2026-66053MEDIUM5.9Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affect...
CVE-2026-57917MEDIUM4.8proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially a...
CVE-2026-57916MEDIUM4.6proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare ar...
CVE-2026-55970MEDIUM6.5Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users a...
CVE-2026-14856MEDIUM6.3A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter ...
CVE-2026-12495MEDIUM5.3Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys M...
CVE-2026-17534MEDIUM5.5Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal ...
CVE-2026-65765MEDIUM6.9Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.1 - Improper limitation of paths...
CVE-2026-65764MEDIUM5.1Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user i...
CVE-2026-16554MEDIUM5.1cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. Th...
CVE-2026-14827MEDIUM6.8The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it in...
CVE-2026-14820MEDIUM5.3The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-log...
CVE-2026-14568MEDIUM6.5The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration Wor...
CVE-2026-14236MEDIUM4.7The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it...
CVE-2026-14203MEDIUM4.8The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML...
CVE-2026-14190MEDIUM6.1The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input...
CVE-2026-13400MEDIUM6.1Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and incl...
CVE-2026-13390MEDIUM5.3The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggrega...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now