2026 CVE Vulnerabilities

43,890 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-62641MEDIUM6.5In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a craft...
CVE-2026-60119MEDIUM5.4Hi.Events before 1.11.0 contains a cross-site scripting vulnerability that allows authenticated attackers with event cre...
CVE-2026-60118MEDIUM6.9Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated ...
CVE-2026-59840MEDIUM4.3A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all v...
CVE-2026-59839MEDIUM5.5A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0...
CVE-2026-59837MEDIUM6.6A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM ...
CVE-2026-23573MEDIUM6.1An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi...
CVE-2026-15699MEDIUM6.3A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the function nlp.extend of the f...
CVE-2026-15698MEDIUM6.3A vulnerability was determined in kofrasa mingo up to 7.2.1. This impacts the function update/updateOne/updateMany of th...
CVE-2026-15697MEDIUM6.3A vulnerability was found in svgdotjs svg.js up to 3.2.5. This affects the function EventTarget.on of the file svgdotjs/...
CVE-2026-11944MEDIUM6.5openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment ...
CVE-2026-58478MEDIUM6.5Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability...
CVE-2026-58475MEDIUM6.1Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a stored cross-site scripting vulnerability that a...
CVE-2026-52837MEDIUM6.9Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule ...
CVE-2026-14903MEDIUM6.5Path traversal in Ivanti  Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary fil...
CVE-2026-14902MEDIUM6.1An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users ...
CVE-2026-10670MEDIUM5.5The CONFIG_USERSPACE verification handler for the k_thread_name_copy() system call (z_vrfy_k_thread_name_copy() in kerne...
CVE-2026-53566MEDIUM6.8Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. This issue affects Citrix Secure Ac...
CVE-2026-62393MEDIUM4.3Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job...
CVE-2026-49488MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. Th...
CVE-2026-15719MEDIUM5.4We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw....
CVE-2026-15718MEDIUM4.3We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw....
CVE-2026-15305MEDIUM6.3Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload elements with allowed...
CVE-2026-12588MEDIUM6An attacker with access to an HX 10.0.0  and previous versions, may send specially-crafted data to the HX console. The m...
CVE-2026-9341MEDIUM4.3The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Di...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now