2026 CVE Vulnerabilities

44,965 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-59097MEDIUM6.9Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remote attackers to creat...
CVE-2026-58580MEDIUM6LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel. ...
CVE-2026-58579MEDIUM5.4RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalize...
CVE-2026-58381MEDIUM6.1A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function whe...
CVE-2026-55950MEDIUM5.9Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux module) allows an u...
CVE-2026-54887MEDIUM4.8Use of Default Cryptographic Key vulnerability in Erlang/OTP ssl (DTLS server) allows predictable DTLS cookie computatio...
CVE-2026-54886MEDIUM4.3Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an auth...
CVE-2026-53422MEDIUM4.3Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to ...
CVE-2026-50282MEDIUM4.9Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and...
CVE-2026-55110MEDIUM6.1A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (COR...
CVE-2026-12166MEDIUM5.5A NULL pointer dereference vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to c...
CVE-2026-58653MEDIUM5.3PraisonAI before 0.1.7 fails to validate that project_id in issue create and update request bodies belongs to the URL wo...
CVE-2026-4772MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defens...
CVE-2026-4770MEDIUM4.6Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defens...
CVE-2026-57764MEDIUM6.5Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions.
CVE-2026-57763MEDIUM6.5Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions.
CVE-2026-57762MEDIUM5.9Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions.
CVE-2026-57760MEDIUM5.3Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Cont...
CVE-2026-57755MEDIUM6.5Contributor Cross Site Scripting (XSS) in Mosaic Gallery &#8211; Advanced Gallery <= 1.2.0 versions.
CVE-2026-57754MEDIUM6.5Contributor Cross Site Scripting (XSS) in Livemesh Addons for WPBakery Page Builder <= 3.9.4 versions.
CVE-2026-57753MEDIUM5.3Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versions.
CVE-2026-57750MEDIUM5.3Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions.
CVE-2026-57747MEDIUM6.5Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions.
CVE-2026-57731MEDIUM6.5Contributor Broken Access Control in Flatsome <= 3.20.5 versions.
CVE-2026-57730MEDIUM4.3Subscriber Broken Access Control in Flatsome <= 3.20.5 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now