2026 CVE Vulnerabilities

43,308 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-15821MEDIUM6.4The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2026-15739MEDIUM6.4The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' ...
CVE-2026-15346MEDIUM6.1The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '...
CVE-2026-12702MEDIUM5.1In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to...
CVE-2026-16910MEDIUM5.5A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers acc...
CVE-2026-15755MEDIUM6.4The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Short...
CVE-2026-15665MEDIUM6.4The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2026-15653MEDIUM6.4The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2026-15648MEDIUM6.4The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attri...
CVE-2026-15464MEDIUM6.4The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Att...
CVE-2026-15334MEDIUM6.4The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress...
CVE-2026-15333MEDIUM6.4The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress...
CVE-2026-12654MEDIUM5.3The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up...
CVE-2026-12689MEDIUM5.4The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its pr...
CVE-2026-12688MEDIUM6.5The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group mem...
CVE-2026-66139MEDIUM4.8OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.
CVE-2026-54422MEDIUM5.5In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, m...
CVE-2026-6454MEDIUM6.4The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and inclu...
CVE-2026-15420MEDIUM4.3The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory ...
CVE-2026-15100MEDIUM6.4The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnore...
CVE-2026-13464MEDIUM5.3The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Ob...
CVE-2026-11922MEDIUM6.5A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST...
CVE-2026-11354MEDIUM5.3The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an...
CVE-2026-49159MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose ...
CVE-2026-44955MEDIUM6.9Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized contr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now