2026 CVE Vulnerabilities

64,751 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-78397MEDIUM4The Link Library WordPress plugin before 7.9.6 does not validate the destination of a user-supplied URL before falling b...
CVE-2026-78394MEDIUM4.1The Link Library WordPress plugin before 7.9.6 does not sanitize a user-supplied destination folder before writing a gen...
CVE-2026-78393MEDIUM6.1The Link Library WordPress plugin before 7.9.6 does not properly escape some parameters before outputting them in the ad...
CVE-2026-19775MEDIUM4.3The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress is vulnerable to authorizat...
CVE-2026-97736MEDIUM5.4tinyauth before 5.1.3 allows rule bypass by appending an allowed route string. This is caused by an unanchored regular e...
CVE-2026-97732MEDIUM5.1IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authenticates client executables by checking for exp...
CVE-2026-97724MEDIUM4.3A prototype pollution vulnerability in Software Mansion React Native Worklets before 0.12.2 allows an attacker-controlle...
CVE-2026-97650MEDIUM4.3A vulnerability has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. A...
CVE-2026-97723MEDIUM5.4madpsy ka9q_ubersdr before 0.1.58 has a stored cross-site scripting (XSS) vulnerability in the chat message rendering fu...
CVE-2026-97649MEDIUM4.7A flaw has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected b...
CVE-2026-97648MEDIUM4.3A vulnerability was detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Aff...
CVE-2026-97647MEDIUM5.3A security vulnerability has been detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207c...
CVE-2026-95811MEDIUM6.5Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl...
CVE-2026-85417MEDIUM6.4Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be reco...
CVE-2026-53493MEDIUM6.9containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI...
CVE-2026-84283MEDIUM6.8Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-stor...
CVE-2026-97636MEDIUM6.5Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-co...
CVE-2026-97368MEDIUM6.3A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInf...
CVE-2026-97366MEDIUM6.3A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function...
CVE-2026-93353MEDIUM5.3copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users ...
CVE-2026-88386MEDIUM5.5libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks. A spec...
CVE-2026-87118MEDIUM5.7The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functiona...
CVE-2026-84403MEDIUM6.2The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access...
CVE-2026-82716MEDIUM4.6The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diag...
CVE-2026-82708MEDIUM6.5The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with acce...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now