2026 CVE Vulnerabilities

64,982 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-13159MEDIUM4.3The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions...
CVE-2026-86170MEDIUM6.3A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /mod...
CVE-2026-86164MEDIUM6.3A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of t...
CVE-2026-86163MEDIUM6.3A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the f...
CVE-2026-86150MEDIUM4.1A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-...
CVE-2026-86206MEDIUM6.9A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is...
CVE-2026-67279MEDIUM6.5RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never att...
CVE-2026-6554MEDIUM5.5libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via bac...
CVE-2026-6244MEDIUM5.5libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zer...
CVE-2026-31912MEDIUM5.5libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instructio...
CVE-2026-31911MEDIUM5.5libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular unco...
CVE-2026-18313MEDIUM4.3rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received fro...
CVE-2026-18238MEDIUM5The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its heade...
CVE-2026-82752MEDIUM5.9Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to store a value ...
CVE-2026-86197MEDIUM5.1Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and ad...
CVE-2026-86194MEDIUM6.9Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing an...
CVE-2026-86192MEDIUM6.5SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys end...
CVE-2026-86191MEDIUM4.3SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint t...
CVE-2026-86187MEDIUM5.9WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing...
CVE-2026-86186MEDIUM6.5AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eigh...
CVE-2026-15550MEDIUM4.3The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and inclu...
CVE-2026-12843MEDIUM5.4The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.6. This is due to ...
CVE-2026-86178MEDIUM5.4Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowin...
CVE-2026-86176MEDIUM4.3NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, S...
CVE-2026-86175MEDIUM6.5NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authen...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now