2026 CVE Vulnerabilities

64,858 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-90552MEDIUM4.3WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlist...
CVE-2026-90551MEDIUM5.3WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the video_fr...
CVE-2026-90550MEDIUM5.3WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorization in the PlayerSkins...
CVE-2026-90549MEDIUM5.3WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndr...
CVE-2026-90548MEDIUM5.3WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGalle...
CVE-2026-90547MEDIUM5.3WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the Bookmark p...
CVE-2026-90546MEDIUM4.3WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the li...
CVE-2026-90545MEDIUM4.3WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the co...
CVE-2026-90544MEDIUM4.3WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the vi...
CVE-2026-90543MEDIUM5.3WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a mis...
CVE-2026-90542MEDIUM5.4WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate that logged-in users can access li...
CVE-2026-90541MEDIUM5.3WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to require authentication in the plugin/TopMen...
CVE-2026-90540MEDIUM4.3WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate watch permissions in the playListA...
CVE-2026-90539MEDIUM5.3WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in t...
CVE-2026-90538MEDIUM5.3WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in pl...
CVE-2026-90536MEDIUM5.3WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the adsInfo API endpoin...
CVE-2026-90534MEDIUM6.5Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST /api/v1/no...
CVE-2026-90533MEDIUM6.5Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any auth...
CVE-2026-10148MEDIUM6.4The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via m...
CVE-2026-90474MEDIUM6.8MCPHub before 1.0.32 contains an authentication bypass vulnerability in its embedded OAuth 2.0 authorization server wher...
CVE-2026-90473MEDIUM5.3msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MA...
CVE-2026-90472MEDIUM5.3msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively de...
CVE-2026-89172MEDIUM5.6Improper protection of physical side channels vulnerability in Microchip AN1044, Microchip AN953, and Microchip SW300052...
CVE-2026-85198MEDIUM6.5The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic S...
CVE-2026-77161MEDIUM6.5The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now