2026 CVE Vulnerabilities

64,982 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-80056MEDIUM5.5Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-78488MEDIUM6.5Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-86310MEDIUM6.3A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown functi...
CVE-2026-86309MEDIUM6.3A flaw has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages...
CVE-2026-86308MEDIUM5.3A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f6138...
CVE-2026-86307MEDIUM4.3A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a061...
CVE-2026-80170MEDIUM6.5Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-80128MEDIUM6.5Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-78487MEDIUM5.5Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-12757MEDIUM6.5The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin f...
CVE-2026-8279MEDIUM5.3The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on ...
CVE-2026-86451MEDIUM4.3Affected versions of MISP allow authenticated users to retrieve object-reference records by UUID through EventGraphTool:...
CVE-2026-86441MEDIUM4.3Affected versions of MISP contain inconsistent authorization checks across dashboard widgets that display organisation i...
CVE-2026-86440MEDIUM5.4Affected versions of MISP insufficiently validate URLs used by dashboard widgets, particularly the Button widget. The ...
CVE-2026-86432MEDIUM5.3commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits depth-pr...
CVE-2026-86425MEDIUM5.5ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method ...
CVE-2026-86423MEDIUM5.5ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the GetList metho...
CVE-2026-86418MEDIUM4.3Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the sa...
CVE-2026-86417MEDIUM4.3Affected versions of MISP inconsistently enforced email-address visibility in DashboardsController::listTemplates(). T...
CVE-2026-86416MEDIUM5.4ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMap...
CVE-2026-86408MEDIUM6.5Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKe...
CVE-2026-86302MEDIUM5.3A vulnerability was found in code-projects Hospital Information System 1.0. Affected by this vulnerability is an unknown...
CVE-2026-80135MEDIUM5.3Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-4945MEDIUM5.3The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Insec...
CVE-2026-12853MEDIUM5.4The Flamingo plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2. Thi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now