2026 CVE Vulnerabilities

64,659 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8353MEDIUM4.8Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inje...
CVE-2026-8347MEDIUM4.3Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog...
CVE-2026-8340MEDIUM4.3Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edit_file_contents perm...
CVE-2026-9277HIGH8.1shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The ...
CVE-2026-8997MEDIUM4.8vifm is vulnerable to a heap buffer overflow during the history merge process when saving the state file (vifminfo.json)...
CVE-2026-8673CRITICAL9.1Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Atta...
CVE-2026-8672MEDIUM5.1Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Common or Default User...
CVE-2026-8671HIGH7.5Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows R...
CVE-2026-8670CRITICAL9.6Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session ID...
CVE-2026-44930CRITICAL9.8An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacke...
CVE-2026-44618MEDIUM5.3Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users a...
CVE-2026-44417HIGH7.5The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that anoth...
CVE-2026-5755MEDIUM6.5Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.2, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to ...
CVE-2026-5740HIGH7.5Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to properly validate ...
CVE-2026-5308HIGH7.5Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request bo...
CVE-2026-4646MEDIUM4.3Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate user-supp...
CVE-2026-4635MEDIUM5.3Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to archive the channe...
CVE-2026-3636MEDIUM4.3Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to sanitize team memb...
CVE-2026-3473HIGH7.1Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file owne...
CVE-2026-25608LOW2.3STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middl...
CVE-2026-25607MEDIUM5.7Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after analyzin...
CVE-2026-25606HIGH8.7A SQL injection vulnerability has been identified in STER. Improper neutralization of input provided by user into multip...
CVE-2026-9011HIGH7.5The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to authorization bypass in al...
CVE-2026-8692MEDIUM4.3The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPress is vulnerable to...
CVE-2026-8684MEDIUM5.3The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now