2026 CVE Vulnerabilities

64,952 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-73321MEDIUM6.5XenForo before 2.3.13 contains an uncontrolled recursion vulnerability in the BBCode parser that allows authenticated at...
CVE-2026-73320MEDIUM6.1XenForo before 2.3.13 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attac...
CVE-2026-73319MEDIUM6.1XenForo before 2.3.13 contains a cross-site scripting vulnerability in the dynamic redirect handler that allows unauthen...
CVE-2026-73310MEDIUM5.9XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any ...
CVE-2026-33391MEDIUM5.4An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient vali...
CVE-2026-33387MEDIUM4.6A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input...
CVE-2026-79603MEDIUM4.3x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued ...
CVE-2026-62437MEDIUM6.5When guests are terminated, various pieces of cleanup need carrying out. The cleaning up of PCI devices which were assig...
CVE-2026-86714MEDIUM5.4PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to ...
CVE-2026-76931MEDIUM6.4The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter...
CVE-2026-2520MEDIUM5.4The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modific...
CVE-2026-18021MEDIUM6.5The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shor...
CVE-2026-17509MEDIUM6.5The WPML Multilingual CMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘elementIds’ parameter ...
CVE-2026-12230MEDIUM6.4The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Stored Cr...
CVE-2026-77654MEDIUM6.1Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, ...
CVE-2026-19614MEDIUM5.3The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue ...
CVE-2026-86590MEDIUM6.3In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passe...
CVE-2026-77132MEDIUM5.3It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization...
CVE-2026-86597MEDIUM6.5Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers ...
CVE-2026-86550MEDIUM6.5NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to i...
CVE-2026-74859MEDIUM6.8The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. A...
CVE-2026-62654MEDIUM6.8A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A special maintenance mode can be activated...
CVE-2026-62653MEDIUM6.8A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The input received over a proprietary commu...
CVE-2026-62652MEDIUM5.3A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware contains binaries from ...
CVE-2026-58113MEDIUM6.1A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now