2026 CVE Vulnerabilities

64,755 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-78313MEDIUM6.5Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-78310MEDIUM4.3Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-97181MEDIUM5.3GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can direct...
CVE-2026-87739MEDIUM6.9An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report ...
CVE-2026-81645MEDIUM5.9Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availa...
CVE-2026-97177MEDIUM6.6A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are en...
CVE-2026-97176MEDIUM4.2A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management sol...
CVE-2026-93662MEDIUM4.3The Events Manager WordPress plugin before 7.4.5 does not force the scope of its logged-in event and location search wh...
CVE-2026-89005MEDIUM6.8The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configura...
CVE-2026-89002MEDIUM6.8The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a u...
CVE-2026-88847MEDIUM4.3The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course...
CVE-2026-88846MEDIUM5.3The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled...
CVE-2026-88845MEDIUM4.3The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on ...
CVE-2026-82850MEDIUM4.3The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticate...
CVE-2026-82849MEDIUM4.3The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progre...
CVE-2026-82195MEDIUM6.5The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret...
CVE-2026-80338MEDIUM6.8The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users...
CVE-2026-74991MEDIUM6.8The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form su...
CVE-2026-97155MEDIUM6.5Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension v...
CVE-2026-96892MEDIUM4.3A flaw has been found in Edimax BR-6428nC 1.16. The impacted element is the function websRedirect of the component gofor...
CVE-2026-97149MEDIUM5.3In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempU...
CVE-2026-96884MEDIUM6.3A security flaw has been discovered in MantisZip up to 0.4.5. Affected by this issue is the function Path.Combine of the...
CVE-2026-96882MEDIUM5.3A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1. Affected by this vulnerability is the functio...
CVE-2026-96881MEDIUM5.3A vulnerability was determined in TaleLin lin-cms-spring-boot up to 0.2.1. Affected is the function getBooks of the file...
CVE-2026-97056MEDIUM6.8SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the opaque session tokenizer (wh...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now