2026 CVE Vulnerabilities

65,007 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-81282MEDIUM6.5Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions.
CVE-2026-81281MEDIUM6.5Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.
CVE-2026-75602MEDIUM6.5OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST...
CVE-2026-85239MEDIUM6.5A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify even...
CVE-2026-85238MEDIUM6.8MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a us...
CVE-2026-84967MEDIUM4.3A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection strin...
CVE-2026-84966MEDIUM5.5An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a lengt...
CVE-2026-84965MEDIUM5.5An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be...
CVE-2026-84963MEDIUM5.3An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusua...
CVE-2026-84962MEDIUM4.2An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google ...
CVE-2026-82525MEDIUM5.5Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to rea...
CVE-2026-75036MEDIUM5.3A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet co...
CVE-2026-75035MEDIUM6.5A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user,...
CVE-2026-53720MEDIUM5.1pymonocypher uses cython to wrap the Monocypher C library. Prior to version 4.0.2.8, the argon2i_32 implementation does ...
CVE-2026-50554MEDIUM5.3Note Mark is an open-source note-taking application. Prior to version 0.19.5, GET /api/books/{bookID}/notes is an unauth...
CVE-2026-85230MEDIUM5.4A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration. Dashboard widge...
CVE-2026-85227MEDIUM6.1MISP contains a reflected Cross-Site Scripting (XSS) vulnerability in the event attribute filtering query builder. The t...
CVE-2026-85226MEDIUM4.3MISP contains an authorization flaw in the OnDemand correlation engine where correlations were calculated solely from ma...
CVE-2026-85210MEDIUM4.3Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registere...
CVE-2026-85177MEDIUM5.4CRMEB through 6.0.0 fails to validate message ownership in the edit_message handler of MessageSystemController.php, allo...
CVE-2026-85135MEDIUM6.3A security flaw has been discovered in ILIAS up to 9.21/10.9/11.2. This affects the function ilObjMediaObjectGUI::upload...
CVE-2026-84971MEDIUM6.5Improper handling of an unexpected value size in the decryption path of a client-side encryption library can cause a fai...
CVE-2026-84970MEDIUM5.8A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library. An actor wh...
CVE-2026-71403MEDIUM6.1A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's `userna...
CVE-2026-63694MEDIUM5Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements use...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now