2026 CVE Vulnerabilities

43,311 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-65014MEDIUM5.3n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoi...
CVE-2026-61392MEDIUM5.3There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain ...
CVE-2026-57599MEDIUM6.6There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the d...
CVE-2026-44192MEDIUM6.6A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traver...
CVE-2026-16551MEDIUM6.9Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB module) allows Excessive Allocation. This issue affe...
CVE-2026-16544MEDIUM6.5A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are ...
CVE-2026-16473MEDIUM4.3A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted aud...
CVE-2026-63264MEDIUM5.3Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3 - The Joomla extension JoomShopping is vuln...
CVE-2026-2406MEDIUM6.5Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industr...
CVE-2026-15787MEDIUM6.4The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu ...
CVE-2026-45820MEDIUM6.6fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with ...
CVE-2026-14322MEDIUM5.3The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created throug...
CVE-2026-16492MEDIUM5.5A weakness has been identified in umijs umi up to 4.6.63. The affected element is the function git.getFileCreateInfo of ...
CVE-2026-16490MEDIUM6.3A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of t...
CVE-2026-63263MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansio...
CVE-2026-63262MEDIUM4.3Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied ...
CVE-2026-16489MEDIUM5.3A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib...
CVE-2026-16488MEDIUM5A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Po...
CVE-2026-63261MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)...
CVE-2026-63260MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)...
CVE-2026-63259MEDIUM4.3Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplie...
CVE-2026-63145MEDIUM4.3Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification ...
CVE-2026-63144MEDIUM6.5Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request s...
CVE-2026-63143MEDIUM4.3Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122...
CVE-2026-63142MEDIUM5Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reportin...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now