2026 CVE Vulnerabilities

64,952 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-81802MEDIUM6.5Unauthenticated Insecure Direct Object References (IDOR) in WpEvently <= 5.6.0 versions.
CVE-2026-81792MEDIUM6.5Incorrect Privilege Assignment vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX woo...
CVE-2026-86519MEDIUM5.3A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /car...
CVE-2026-86518MEDIUM6.3A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file...
CVE-2026-86517MEDIUM6.3A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query ...
CVE-2026-86516MEDIUM4.7A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown fun...
CVE-2026-86515MEDIUM4.3A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/...
CVE-2026-86514MEDIUM6.3A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txt...
CVE-2026-86513MEDIUM5.3A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function Tr...
CVE-2026-86512MEDIUM6.3A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/M...
CVE-2026-86511MEDIUM5.3A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDe...
CVE-2026-75811MEDIUM5.8Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify har...
CVE-2026-75810MEDIUM5.7Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing...
CVE-2026-75809MEDIUM5.9Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and d...
CVE-2026-75808MEDIUM5.7Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-serv...
CVE-2026-18023MEDIUM5.7Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose ...
CVE-2026-16006MEDIUM5.7Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user t...
CVE-2026-16005MEDIUM5.8Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a craft...
CVE-2026-16004MEDIUM5.9Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary P...
CVE-2026-12962MEDIUM5.3A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local...
CVE-2026-76977MEDIUM4.3SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated at...
CVE-2026-76971MEDIUM6.5Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker...
CVE-2026-76968MEDIUM6.5SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacke...
CVE-2026-76963MEDIUM4.3Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated att...
CVE-2026-76962MEDIUM4.3SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functional...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now