2026 CVE Vulnerabilities

43,494 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-16449MEDIUM6.3A vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. The impacted elem...
CVE-2026-65051MEDIUM6.9Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability tha...
CVE-2026-56584MEDIUM5.3HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software...
CVE-2026-47122MEDIUM4.2Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `...
CVE-2026-16448MEDIUM6.3A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-32...
CVE-2026-11876MEDIUM5In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/stack` endpoint (`get_deployed_stack`) lacks proper ...
CVE-2026-9499MEDIUM6.3An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is ...
CVE-2026-59848MEDIUM5.3A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep ...
CVE-2026-47121MEDIUM6.1Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `re...
CVE-2026-8285MEDIUM4.3Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc. FlexCity allows Exces...
CVE-2026-8284MEDIUM6.1URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCity allows Input Data ...
CVE-2026-6792MEDIUM6.5Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access ...
CVE-2026-16403MEDIUM6.5Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16397MEDIUM6.5Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.
CVE-2026-65009MEDIUM5.3OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint th...
CVE-2026-64628MEDIUM5.4Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where the XSS detection s...
CVE-2026-64627MEDIUM6.9Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema disclosure vulnerabilit...
CVE-2026-59845MEDIUM5.9A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; durin...
CVE-2026-59844MEDIUM6.5A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large leng...
CVE-2026-59843MEDIUM6.5A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN...
CVE-2026-59842MEDIUM5.3A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than...
CVE-2026-16461MEDIUM6.5A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), v...
CVE-2026-1372MEDIUM4.3The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and in...
CVE-2026-15145MEDIUM6.4The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored ...
CVE-2026-8593MEDIUM5.3Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now