2026 CVE Vulnerabilities

64,734 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-93030MEDIUM6.5FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity in...
CVE-2026-97864MEDIUM5.3A vulnerability has been found in GibbonEdu Gibbon up to 30.0.01. The affected element is the function makeBlock of the ...
CVE-2026-97222MEDIUM5.5A heap use-after-free flaw was found in Gnumeric. When a user opens a crafted Gnumeric workbook containing a malformed S...
CVE-2026-80431MEDIUM6.8Out-of-bounds Write in the natural width branch of the text sizing protocol in kitty from 0.40.0 before 0.49.0 allows a ...
CVE-2026-80430MEDIUM4.6Improper Link Resolution Before File Access in the drag source staging path of the drag and drop protocol in kitty from ...
CVE-2026-100190MEDIUM6.3The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site script injection (XSS)...
CVE-2026-100187MEDIUM6.9The Onion module in AIL Framework contained a performance shortcut in its URL extraction logic that accepted URLs as val...
CVE-2026-100177MEDIUM6.3The AIL Framework crawler task creation API (api_add_crawler_task) contained an insufficient authorization check when a ...
CVE-2026-100174MEDIUM5.1The AIL Framework tag selector component (var/www/static/js/tags.js) is vulnerable to stored cross-site scripting (XSS)....
CVE-2026-78902MEDIUM6.1Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via t...
CVE-2026-27867MEDIUM4.8An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration actio...
CVE-2026-97863MEDIUM6.3The cisco_firesight_manager_ACL_rule_export module in misp-modules generates a shell script (.sh) that authenticates to ...
CVE-2026-92573MEDIUM6.5Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message d...
CVE-2026-88848MEDIUM4.2The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50 does not verify that a course a member asks to enrol in is c...
CVE-2026-86837MEDIUM5.3The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored deta...
CVE-2026-80514MEDIUM5.3The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address heade...
CVE-2026-6088MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-6087MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-6086MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-6085MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-6084MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-6083MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-6082MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-96448MEDIUM6.6A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management ...
CVE-2026-93747MEDIUM6.4The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in v...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now