2026 CVE Vulnerabilities

64,997 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-82729MEDIUM6.3Inefficient Algorithmic Complexity vulnerability in elixir-mint mint allows a remote HTTP server to exhaust CPU on the c...
CVE-2026-81859MEDIUM6.2CP4BA - IBM Enterprise Records could allow a local attacker to obtain sensitive information due to the use of a broken o...
CVE-2026-19727MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information...
CVE-2026-14466MEDIUM4.3It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS adm...
CVE-2026-85522MEDIUM5.3A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Affected by this vulnerability is the function creat...
CVE-2026-85517MEDIUM5.3A flaw has been found in code-projects Vehicle Management System 1.0. The impacted element is an unknown function of the...
CVE-2026-77818MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information...
CVE-2026-19081MEDIUM4.3Missing Authorization vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Accessing Functionality ...
CVE-2026-19057MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gastromenum Gastro...
CVE-2026-85514MEDIUM6.3A security vulnerability has been detected in StackStorm st2 up to 3.9.0. Impacted is an unknown function of the file st...
CVE-2026-85513MEDIUM6.3A weakness has been identified in StackStorm st2 up to 3.9.0. This issue affects the function assert_user_is_admin_if_us...
CVE-2026-82309MEDIUM4.3Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a fo...
CVE-2026-74237MEDIUM6.5GFI Exinda AI and ClearView before 7.6.5 contains an argument injection vulnerability in the Tools Iperf Client function...
CVE-2026-74236MEDIUM6.5GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the diagnostic file deletion handler...
CVE-2026-74235MEDIUM4.9GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the system maintenance configuration...
CVE-2026-85615MEDIUM6.4Openpanel before 2.3.0 contains an insecure direct object reference vulnerability in the report.getLayouts and report.re...
CVE-2026-85611MEDIUM6.4OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts ...
CVE-2026-85603MEDIUM6.5Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to v...
CVE-2026-85602MEDIUM5.3The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate b...
CVE-2026-85601MEDIUM5.4Grav Admin before 2.0.20 fails to sanitize output from marked.parse() before injecting it into the DOM via Svelte's {@ht...
CVE-2026-85600MEDIUM5.4Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tH...
CVE-2026-85598MEDIUM6.4Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page e...
CVE-2026-85593MEDIUM5.4phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks...
CVE-2026-85589MEDIUM5.3phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints search...
CVE-2026-85588MEDIUM5.3phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attacker...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now