2026 CVE Vulnerabilities

64,868 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-88790MEDIUM4.8A security vulnerability has been detected in proma-ai Proma up to 0.19.37. Affected is the function resolveTargetPath o...
CVE-2026-45763MEDIUM5.9Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. St...
CVE-2026-12683MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation...
CVE-2026-12682MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation...
CVE-2026-9161MEDIUM5.3Observable response discrepancy vulnerability in DernekPlus Website Template allows Account Footprinting. This issue af...
CVE-2026-88038MEDIUM4.8cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2...
CVE-2026-85544MEDIUM6.1Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physi...
CVE-2026-85543MEDIUM4.3Some Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated ...
CVE-2026-17038MEDIUM6.9DrEryk Gabinet before 11.5.0 uses hard-coded API credentials in its ticket reporting component. These credentials can be...
CVE-2026-88859MEDIUM6.3A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML emai...
CVE-2026-84828MEDIUM6.5A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can e...
CVE-2026-78085MEDIUM6.9Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery mana...
CVE-2026-78374MEDIUM6.9Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0 - The f...
CVE-2026-78303MEDIUM6.9Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property...
CVE-2026-78084MEDIUM6.9Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4 - The gal...
CVE-2026-5399MEDIUM6.4The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider field in User Profi...
CVE-2026-15889MEDIUM6.4The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Content in all ve...
CVE-2026-88288MEDIUM6.5GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with va...
CVE-2026-88284MEDIUM4.9GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF SetUser requests, allowing an authenticated ad...
CVE-2026-88283MEDIUM4.9GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticate...
CVE-2026-88281MEDIUM4.9GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements in ONVIF DeleteUsers requests, allowing an authenti...
CVE-2026-88280MEDIUM4.9GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser password into a fixed stack field, allowing an authenticate...
CVE-2026-88279MEDIUM4.9GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allow...
CVE-2026-88270MEDIUM6.5GeoVision GV-LPC2211 V1.13 allows a Guest user to enter SSVR firmware-upgrade mode and disrupt live services before any ...
CVE-2026-88269MEDIUM6.5GeoVision GV-LPC2211 V1.13 allows a Guest user to retrieve persistent device configuration containing plaintext administ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now