2026 CVE Vulnerabilities

44,078 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-11869MEDIUM5.3The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-proces...
CVE-2026-15138MEDIUM6.3A security vulnerability has been detected in tumf mcp-text-editor up to 1.0.2. This issue affects the function _validat...
CVE-2026-47646MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allo...
CVE-2026-54779MEDIUM5.9CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ...
CVE-2026-54778MEDIUM6.2CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ...
CVE-2026-54776MEDIUM4.4CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ...
CVE-2026-54775MEDIUM6.5CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ...
CVE-2026-54773MEDIUM5.9CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ...
CVE-2026-15131MEDIUM4.3Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass ...
CVE-2026-15130MEDIUM4.3Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypa...
CVE-2026-15128MEDIUM6.1Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbit...
CVE-2026-15127MEDIUM6.1Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbit...
CVE-2026-15124MEDIUM4.3Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypas...
CVE-2026-15109MEDIUM6.5Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to obtain potentially sens...
CVE-2026-15108MEDIUM4.3Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to ...
CVE-2026-15105MEDIUM6.3A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the...
CVE-2026-5923MEDIUM6Malicious use of a stolen cookie might allow modifications to the contents of the IP phone’s webpage.
CVE-2026-5922MEDIUM5.9The IP phone might use malicious input stored in configuration parameters and render it as content for the WebUI’s webpa...
CVE-2026-55877MEDIUM6.1Symfony UX is a JavaScript ecosystem for Symfony. From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux_icon() T...
CVE-2026-54777MEDIUM6.5CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ...
CVE-2026-48492MEDIUM6.5Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpo...
CVE-2026-39179MEDIUM6.3A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via t...
CVE-2026-39178MEDIUM6.3A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via t...
CVE-2026-8472MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and 19....
CVE-2026-7492MEDIUM5.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 1...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now