2026 CVE Vulnerabilities

44,807 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-13199MEDIUM5.1EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced non-random KASLR and RNG seed values. This resul...
CVE-2026-8309MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information...
CVE-2026-8306MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information...
CVE-2026-7380MEDIUM6.1Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Techno...
CVE-2026-58315MEDIUM5.1Cross-site request forgery vulnerability exists in SEIKO EPSON Web Config. If a user views a malicious page while logged...
CVE-2026-57870MEDIUM5.3Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document template...
CVE-2026-10834MEDIUM4.6The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied profile ima...
CVE-2026-26053MEDIUM5.3An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator ...
CVE-2026-42147MEDIUM4.9Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34198MEDIUM5.3Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34170MEDIUM4.3Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-11328MEDIUM6.4The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title ...
CVE-2026-53648MEDIUM5.1FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.1, downloadable product fi...
CVE-2026-53647MEDIUM6.9FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `ser...
CVE-2026-13356MEDIUM6.3A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the brows...
CVE-2026-53642MEDIUM5.3FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when the "Requ...
CVE-2026-53641MEDIUM4.8FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a stored cros...
CVE-2026-59710MEDIUM6.1showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/ta...
CVE-2026-43927MEDIUM6.9FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, a race condition in the...
CVE-2026-43925MEDIUM6.9FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, an unauthenticated mass...
CVE-2026-41899MEDIUM6.5Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-38979MEDIUM5.4ajenti through v2.2.13 has a clickjacking weakness in the browser-facing login and administrative UI. In ajenti-core/aj/...
CVE-2026-38973MEDIUM4.4mrubyc through release3.4.1 was found to contain an out-of-bounds read in builtin missing-method lookup inside mrbc_find...
CVE-2026-34167MEDIUM5Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34050MEDIUM6.5Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now