2026 CVE Vulnerabilities

65,063 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-78609MEDIUM5.4Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via...
CVE-2026-78602MEDIUM5.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead ...
CVE-2026-78601MEDIUM5.5Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authori...
CVE-2026-78599MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can ...
CVE-2026-78598MEDIUM5.4Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiti...
CVE-2026-78594MEDIUM4.9Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Exces...
CVE-2026-78591MEDIUM6.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can ...
CVE-2026-78588MEDIUM6.5Allocation of Resources Without Limits or Throttling (CWE-770) in Filebeat can lead to a denial of service via Excessive...
CVE-2026-78586MEDIUM6.5Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A...
CVE-2026-78584MEDIUM4.3Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query Sys...
CVE-2026-78153MEDIUM5.3The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking it against ...
CVE-2026-77794MEDIUM5.3The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calcu...
CVE-2026-77793MEDIUM5.3The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-si...
CVE-2026-2811MEDIUM5.4The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient input saniti...
CVE-2026-2688MEDIUM6.5The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter along...
CVE-2026-17563MEDIUM5.3The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing ...
CVE-2026-14255MEDIUM5.5A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an Uncontrolled Recursion vul...
CVE-2026-10821MEDIUM6.6The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origins before w...
CVE-2026-81269MEDIUM5.3Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field version...
CVE-2026-81205MEDIUM5.3Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Acti...
CVE-2026-81201MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Monster Men...
CVE-2026-81167MEDIUM4.8Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Sug...
CVE-2026-81166MEDIUM5.3Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Dig...
CVE-2026-81165MEDIUM5.3Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from ...
CVE-2026-81164MEDIUM5.4Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF version...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now