2026 CVE Vulnerabilities

64,868 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-88268MEDIUM6.5GeoVision GV-LPC2211 V1.13 contains an authenticated stack buffer overflow in SSVR fragment reassembly that allows a val...
CVE-2026-88265MEDIUM5.6A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to...
CVE-2026-88264MEDIUM5.6A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redi...
CVE-2026-42808MEDIUM6.8An issue was discovered in Bosch Sensortec COINES_SDK versions 2.0 through 2.11.  The host streaming API function {{c...
CVE-2026-42806MEDIUM4.3An out-of-bounds read vulnerability was discovered in the Bosch BME690 SensorAPI (C-driver) in version v1.0.3 and prior,...
CVE-2026-88770MEDIUM6.5A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The iss...
CVE-2026-88763MEDIUM5.9A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure commun...
CVE-2026-82582MEDIUM5.3An authorization bypass vulnerability exists in SHIRASAGI through a user-controlled key, which may allow an unauthorized...
CVE-2026-81635MEDIUM5.1A cross-site scripting vulnerability exists in SHIRASAGI, which may allow an attacker to execute an arbitrary script in ...
CVE-2026-19840MEDIUM6.5The Notiqoo WordPress plugin before 1.4.14 does not have capability checks on several of its AJAX actions and builds th...
CVE-2026-0304MEDIUM4.8A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged ...
CVE-2026-85645MEDIUM6.1The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflect...
CVE-2026-0309MEDIUM4A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypas...
CVE-2026-0307MEDIUM5.9Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allows a local user to ...
CVE-2026-0306MEDIUM5.8A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enable...
CVE-2026-0305MEDIUM4.3An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to ...
CVE-2026-75880MEDIUM6.5An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excess...
CVE-2026-57822MEDIUM6.5When the broker is processing message-based management requests, sent by an authenticated messaging client that is autho...
CVE-2026-4657MEDIUM6.4The Easy Google Fonts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the control_selectors meta f...
CVE-2026-18594MEDIUM4.3The Advanced Contact form 7 DB plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inc...
CVE-2026-18386MEDIUM4.9The WP BackItUp Community Edition plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and i...
CVE-2026-15823MEDIUM4.3The Builderall Cheetah For Wp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c...
CVE-2026-15820MEDIUM6.4The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Photo Module 'attribu...
CVE-2026-15796MEDIUM6.4The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'bg_video_service_url...
CVE-2026-87870MEDIUM6.4The Ninja Forms - Scheduled Exports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API Param...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now