2026 CVE Vulnerabilities

43,225 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-73140MEDIUM5.3Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report ex...
CVE-2026-19519MEDIUM4.3A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked...
CVE-2026-19518MEDIUM6.5Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipu...
CVE-2026-19517MEDIUM6.5Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerabilit...
CVE-2026-19391MEDIUM6.5A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the ...
CVE-2026-8158MEDIUM5.3The Signed Video Framework contained a  buffer overflow issue which could lead the application using this framework to ...
CVE-2026-6505MEDIUM5.1The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to priv...
CVE-2026-6181MEDIUM5.9The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after...
CVE-2026-5304MEDIUM5.7An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerabil...
CVE-2026-5303MEDIUM5.7The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to priv...
CVE-2026-18348MEDIUM4.1Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst...
CVE-2026-14549MEDIUM4.3The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of ...
CVE-2026-14548MEDIUM6.5The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of ...
CVE-2026-12052MEDIUM5.2The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm_cth in subsys/usb/device_next/class/usbd_cdc_ncm....
CVE-2026-12051MEDIUM4.6The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer der...
CVE-2026-11894MEDIUM5.9The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the...
CVE-2026-16974MEDIUM6.4The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site ...
CVE-2026-11893MEDIUM5.9The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL60x/BL70x/BL61x), bt_bflb_send() in drivers/bluetoo...
CVE-2026-24330MEDIUM6.5A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a mali...
CVE-2026-24329MEDIUM4.9A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed payload i...
CVE-2026-66779MEDIUM6.3Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker co...
CVE-2026-66778MEDIUM5.3SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. A...
CVE-2026-66777MEDIUM5.9SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. D...
CVE-2026-66776MEDIUM5.9SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under spec...
CVE-2026-66775MEDIUM4.3SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthent...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now