2026 CVE Vulnerabilities

64,982 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-86416MEDIUM5.4ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMap...
CVE-2026-86408MEDIUM6.5Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKe...
CVE-2026-86302MEDIUM5.3A vulnerability was found in code-projects Hospital Information System 1.0. Affected by this vulnerability is an unknown...
CVE-2026-80135MEDIUM5.3Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-4945MEDIUM5.3The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Insec...
CVE-2026-12853MEDIUM5.4The Flamingo plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2. Thi...
CVE-2026-78325MEDIUM6.9Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allow...
CVE-2026-2390MEDIUM6.4The Powerkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lazy Load module's image processi...
CVE-2026-86351MEDIUM6.1Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with...
CVE-2026-86294MEDIUM4.3A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unkno...
CVE-2026-85640MEDIUM6.3Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdate...
CVE-2026-85201MEDIUM6.8In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-...
CVE-2026-82325MEDIUM6.8A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated...
CVE-2026-77699MEDIUM5Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to l...
CVE-2026-77697MEDIUM6.3Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Ext...
CVE-2026-86347MEDIUM6.5Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry...
CVE-2026-86293MEDIUM6.5A flaw has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this vulnerability is an unknown ...
CVE-2026-86291MEDIUM6.3A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. This impacts an unknown funct...
CVE-2026-77698MEDIUM5.7Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to ...
CVE-2026-86342MEDIUM4.3Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview ...
CVE-2026-86332MEDIUM6.5A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResou...
CVE-2026-86289MEDIUM4.3A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/g...
CVE-2026-86288MEDIUM6.3A vulnerability has been found in ModelCloud GPTQModel up to 7.2.0. This vulnerability affects unknown code of the file ...
CVE-2026-86285MEDIUM4.3A vulnerability was detected in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::ge...
CVE-2026-84186MEDIUM6.9Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now