2026 CVE Vulnerabilities

64,922 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-79588MEDIUM4.3U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of administration credentials over HTTP.
CVE-2026-78971MEDIUM4.6In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attac...
CVE-2026-78742MEDIUM6.1Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction.
CVE-2026-78741MEDIUM6.1Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature.
CVE-2026-78738MEDIUM6.1Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Document management file upload feature.
CVE-2026-78635MEDIUM5The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to ...
CVE-2026-78631MEDIUM5.5The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log le...
CVE-2026-78630MEDIUM6.7The Okta Access Gateway does not neutralize shell metacharacters in SNMP configuration values before a privileged script...
CVE-2026-78629MEDIUM5.5The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's poli...
CVE-2026-78622MEDIUM6The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before ...
CVE-2026-19625MEDIUM5.3When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1"...
CVE-2026-85630MEDIUM6.1HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process...
CVE-2026-85485MEDIUM6.1HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping. The Table fo...
CVE-2026-85484MEDIUM6.1HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without...
CVE-2026-79905MEDIUM5.4Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-...
CVE-2026-78627MEDIUM5.5The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The cred...
CVE-2026-78626MEDIUM6.5The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rul...
CVE-2026-78625MEDIUM6.7The Okta Access Gateway does not sanitize dashboard label values before writing them into generated PHP configuration fi...
CVE-2026-78624MEDIUM4.9The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. ...
CVE-2026-78620MEDIUM4.9The Okta Access Gateway Kerberos configuration handler does not validate file paths specified in event payloads before w...
CVE-2026-78579MEDIUM6.5The Okta Access Gateway does not sanitize SAML assertion attribute values before interpolating them into LDAP search fil...
CVE-2026-78574MEDIUM6.3The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive...
CVE-2026-78560MEDIUM6.5The Okta Access Gateway includes an optional pass-through authentication source that accepts user identity from a client...
CVE-2026-78552MEDIUM4.9The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field...
CVE-2026-78550MEDIUM6.6The Okta Access Gateway management console passes user-supplied input to eval() without sanitization during an authentic...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now