2026 CVE Vulnerabilities

65,007 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-85084MEDIUM6.3Out-of-bounds Write and Improper Validation of Array Index vulnerability in Samsung Open Source TizenFX Samsung/TizenFX ...
CVE-2026-85040MEDIUM4.7A weakness has been identified in ZhongBangKeJi CRMEB up to 6.0.0. Affected by this vulnerability is the function eval o...
CVE-2026-85021MEDIUM4.3A vulnerability was determined in langgenius dify 1.13.0. Affected is the function router.replace of the file web/app/(s...
CVE-2026-82918MEDIUM5.5XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external entity refere...
CVE-2026-78000MEDIUM5.3Joomla Extension - j2commerce.com - Reflected XSS via `filter_tag`, `pricefrom` and `priceto` in J2Store 1.0.0-3.3.21, 4...
CVE-2026-74769MEDIUM6.5Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability in the RES...
CVE-2026-74768MEDIUM4.1Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Server-Side Request Forgery (SSRF) vulnerability ...
CVE-2026-71224MEDIUM4.7A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untru...
CVE-2026-71222MEDIUM6.3A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute m...
CVE-2026-71219MEDIUM4.7A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with a...
CVE-2026-68860MEDIUM6.8Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Reliance on Data/Memory Layout vulnerability. An ...
CVE-2026-3852MEDIUM6.4The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `skype_url` shortcode attribute of the...
CVE-2026-2573MEDIUM6.4The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerabl...
CVE-2026-17539MEDIUM5.9RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL ...
CVE-2026-15933MEDIUM6.9OptimiDoc Server (On-Premise) stores credentials for external services in cleartext. An authenticated administrator can ...
CVE-2026-84888MEDIUM4.3A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. This vulnerability affects the function shell_exec o...
CVE-2026-84887MEDIUM4.3A vulnerability was identified in simular-ai Agent-S up to 0.3.2. Affected by this issue is some unknown functionality o...
CVE-2026-84886MEDIUM5.3A vulnerability was determined in simular-ai Agent-S up to 0.3.2. Affected by this vulnerability is the function ImageDa...
CVE-2026-84885MEDIUM4.3A vulnerability has been found in simular-ai Agent-S 0.3.1/0.3.2. This impacts an unknown function of the file code_agen...
CVE-2026-84857MEDIUM5.3A flaw has been found in sigoden aichat up to 0.30.4. This affects an unknown function of the file src/serve.rs of the c...
CVE-2026-84856MEDIUM5.3A vulnerability was detected in rowboatlabs rowboat up to 0.9.1. The impacted element is the function request.text/req.j...
CVE-2026-84852MEDIUM4.4A security vulnerability has been detected in Reader Tools PDF Reader App 98.8 on Android. The affected element is the f...
CVE-2026-75137MEDIUM6.1UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recov...
CVE-2026-75136MEDIUM6.1UpSignOn for Windows before 7.19.0 contains an insecure credential storage vulnerability that allows local attackers to ...
CVE-2026-75135MEDIUM6.1UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recov...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now