2026 CVE Vulnerabilities

61,679 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-11511LOW3.5A weakness has been identified in Bolt CMS up to 3.7.5. This vulnerability affects unknown code of the file src/Storage/...
CVE-2026-50752HIGH7.4A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacke...
CVE-2026-50751CRITICAL9.3A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows ...
CVE-2026-47430HIGH7.5## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body ...
CVE-2026-3011MEDIUM6.4The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'su...
CVE-2026-11569MEDIUM5.4A flaw was found in Quay. The filedrop endpoint accepts any mime type without validation, allowing an authenticated user...
CVE-2026-11510MEDIUM6.3A security flaw has been discovered in CodeAstro Leave Management System 1.0. This affects an unknown part of the file /...
CVE-2026-11509MEDIUM6.3A vulnerability was identified in CodeAstro Leave Management System 1.0. Affected by this issue is some unknown function...
CVE-2026-11508MEDIUM6.3A vulnerability was determined in CodeAstro Leave Management System 1.0. Affected by this vulnerability is an unknown fu...
CVE-2026-11507MEDIUM6.3A vulnerability was found in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /admin/d...
CVE-2026-11506MEDIUM6.3A vulnerability has been found in CodeAstro Leave Management System 1.0. This impacts an unknown function of the file /a...
CVE-2026-11505MEDIUM5A flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an...
CVE-2026-11504HIGH8.8A vulnerability was detected in Tenda CX12L 16.03.53.12. The impacted element is the function setSchedWifi of the file /...
CVE-2026-9506HIGH8.7This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController compo...
CVE-2026-11503HIGH8.8A security vulnerability has been detected in Tenda CX12L 16.03.53.12. The affected element is the function form_fast_se...
CVE-2026-11502LOW3.1A weakness has been identified in JeecgBoot up to 3.9.2. Impacted is the function HttpServletResponse.sendRedirect of th...
CVE-2026-11501HIGH7.3A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This issue affect...
CVE-2026-11500MEDIUM5A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the f...
CVE-2026-41724MEDIUM5.4VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with ...
CVE-2026-41723HIGH8VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with ...
CVE-2026-41722MEDIUM5.4VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with ...
CVE-2026-3238HIGH7.5A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protoc...
CVE-2026-11499CRITICAL9.8A vulnerability was determined in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formDOMAINBLK of th...
CVE-2026-11498HIGH8.8A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. Affected by this issue is the function asp_voip_Ot...
CVE-2026-11497HIGH8.8A vulnerability has been found in D-Link DCS-5615 1.01.00. Affected by this vulnerability is an unknown functionality of...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now