2026 CVE Vulnerabilities

43,311 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-15646MEDIUM6.4The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attri...
CVE-2026-15448MEDIUM6.5The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order...
CVE-2026-15404MEDIUM6.4The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and inc...
CVE-2026-15394MEDIUM6.4The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross...
CVE-2026-15348MEDIUM6.3The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all...
CVE-2026-14481MEDIUM6.4The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerabl...
CVE-2026-13119MEDIUM6.5The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'stan...
CVE-2026-13009MEDIUM6.5The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Param...
CVE-2026-9729MEDIUM6.4The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_noti...
CVE-2026-9635MEDIUM6.4The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parame...
CVE-2026-59677MEDIUM6.8A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined ...
CVE-2026-9577MEDIUM4.8The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before ref...
CVE-2026-9066MEDIUM6.1The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asse...
CVE-2026-59676MEDIUM5.8A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user ...
CVE-2026-63226MEDIUM6.9Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port for...
CVE-2026-6390MEDIUM6.8A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one ...
CVE-2026-7120MEDIUM5.3@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the ...
CVE-2026-21723MEDIUM5.3The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates ...
CVE-2026-16653MEDIUM5.5A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the ...
CVE-2026-16631MEDIUM5.3A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/p...
CVE-2026-38763MEDIUM5.5An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the...
CVE-2026-16630MEDIUM5.3A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the funct...
CVE-2026-16629MEDIUM5.3A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the ...
CVE-2026-16628MEDIUM5.3A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec o...
CVE-2026-64795MEDIUM5.4Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provide...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now