2026 CVE Vulnerabilities

43,635 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-44251MEDIUM6.5Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and abov...
CVE-2026-2594MEDIUM6.4The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi...
CVE-2026-33754MEDIUM6.5Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.9.0 and abov...
CVE-2026-44452MEDIUM5.9h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientH...
CVE-2026-44434MEDIUM5.3Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit dc...
CVE-2026-62826MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-58643MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an u...
CVE-2026-45334MEDIUM5.3Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the content-locking feature ret...
CVE-2026-44176MEDIUM6Kirby is an open-source content management system. Versions prior to 4.9.1 and 5.4.1 do not check the `pages.access` per...
CVE-2026-14782MEDIUM4.9The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Cu...
CVE-2026-13713MEDIUM6.2YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on ...
CVE-2026-61378MEDIUM6.8A divide-by-zero vulnerability in the Productivity Suite allows a local attacker to cause a division by zero leading to...
CVE-2026-60073MEDIUM5.9An out-of-bounds read in the Productivity Suite allows a physical attacker to control the length of data sent to a USB ...
CVE-2026-57896MEDIUM6.9An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupti...
CVE-2026-36425MEDIUM6.5An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user...
CVE-2026-33731MEDIUM6.5WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook handler at plugin/Aut...
CVE-2026-62299MEDIUM5.3CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an ...
CVE-2026-61718MEDIUM5.4bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb w...
CVE-2026-60140MEDIUM6.9An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupti...
CVE-2026-54728MEDIUM6.1bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). Prior to BunkerWeb 1.6.12 and BunkerWeb ...
CVE-2026-15449MEDIUM5.8A time-of-check to time-of-use (TOCTOU) flaw in the illumos data-link pseudo-driver (dld) affects handling of the DLDIOC...
CVE-2026-53536MEDIUM5.3Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/signed download endp...
CVE-2026-53535MEDIUM5.9Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the git-sync feature clones a user-conf...
CVE-2026-47089MEDIUM4.3An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin acces...
CVE-2026-47085MEDIUM4An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxk...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now