2026 CVE Vulnerabilities

44,013 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-17596MEDIUM6.3Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:cre...
CVE-2026-17595MEDIUM5.3Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:select...
CVE-2026-17594HIGH8.2Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in th...
CVE-2026-17593HIGH7.2An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permissi...
CVE-2026-14644HIGH8.6Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with...
CVE-2026-66059MEDIUM5.3Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass expose...
CVE-2026-62996MEDIUM6.9Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From...
CVE-2026-62992MEDIUM6.9Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prio...
CVE-2026-48093MEDIUM6.5The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting (XSS) through the ex...
CVE-2026-19210MEDIUM6.3A vulnerability has been found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of...
CVE-2026-19209LOW3.5A flaw has been found in SourceCodester Photo Share Website 1.0. The affected element is an unknown function of the file...
CVE-2026-19208LOW3.7A vulnerability was detected in WonderTrader up to 0.9.9. Impacted is the function TraderDD::queryTrades of the file src...
CVE-2026-19264CRITICAL9.8Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied pat...
CVE-2026-19207LOW2.4A security vulnerability has been detected in PHPGurukul Company Visitor Management System 1.0. This issue affects some ...
CVE-2026-18497HIGH7.1A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for p...
CVE-2026-66914CRITICAL9.2Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated...
CVE-2026-61477LOW2.3An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline ...
CVE-2026-37171MEDIUM5.9A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one ...
CVE-2026-19206MEDIUM5.3A security flaw has been discovered in MZ Automation libiec61850 up to 1.6.1. This affects the function SVReceiver_stopT...
CVE-2026-16637MEDIUM6.5OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlis...
CVE-2026-15570HIGH7.1An improper restriction of URL schemes and destinations in the SmartCenter browserseturl command in the Telefunken TE245...
CVE-2026-66838MEDIUM5.9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgr...
CVE-2026-66494HIGH8.7Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unaut...
CVE-2026-56794MEDIUM6.5Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A lo...
CVE-2026-56793CRITICAL9.8Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now