2026 CVE Vulnerabilities

43,894 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-58228MEDIUM5.1Cross-site scripting vulnerability in phoenixframework phoenix_live_view allows an attacker to bypass URL scheme validat...
CVE-2026-49971MEDIUM6.1Laravel-Mediable before 7.0.0 contains a stored cross-site scripting vulnerability that allows authenticated or anonymou...
CVE-2026-14906MEDIUM5.3Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within t...
CVE-2026-61505MEDIUM6.9Rejetto HFS 3.0.0 through 3.2.0 allows path traversal through the lang query parameter, permitting a remote unauthentica...
CVE-2026-61504MEDIUM5.4Rejetto HFS 3.0.0 through 3.2.0 does not escape file names in its fallback "basic" web listing, and this listing can be ...
CVE-2026-61503MEDIUM6.9Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint depending on whether the ...
CVE-2026-61502MEDIUM5.1Rejetto HFS 3.0.0 through 3.2.0 accepts state-changing API requests via the GET method and exempts GET requests from its...
CVE-2026-61501MEDIUM6.1Rejetto HFS 3.0.0 through 3.2.0 renders log entries in the administration panel as HTML without sanitization. A remote u...
CVE-2026-60103MEDIUM6.8Blender 3.0.0 through 5.1.2 contains an out-of-bounds read vulnerability that allows attackers to trigger a crash or rea...
CVE-2026-53365MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix zerocopy completion for multi-skb...
CVE-2026-53364MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix memory leak in hci_le_big_...
CVE-2026-15559MEDIUM6.3A vulnerability was detected in CodeAstro Simple Online Leave Management System 1.0. This affects an unknown part of the...
CVE-2026-62147MEDIUM6.5The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API respons...
CVE-2026-15558MEDIUM6.3A security vulnerability has been detected in CodeAstro Simple Online Leave Management System 1.0. Affected by this issu...
CVE-2026-9824MEDIUM4.3Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels per...
CVE-2026-6541MEDIUM4.3Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration change...
CVE-2026-4765MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in the RD Station Conversas chat. The vulnerability resides in the ‘name...
CVE-2026-61985MEDIUM5.3Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectl...
CVE-2026-61983MEDIUM5.3Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Acc...
CVE-2026-61977MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-sea...
CVE-2026-61976MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Ele...
CVE-2026-61975MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-re...
CVE-2026-61970MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in Themeisle Auto Featured Image (Auto Post Thumbnail) auto-post-thumbn...
CVE-2026-61968MEDIUM5.4Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control ...
CVE-2026-61958MEDIUM5.4Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now