2026 CVE Vulnerabilities

64,760 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-67219MEDIUM6RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, add_binding/3...
CVE-2026-66080MEDIUM5.9RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.11, 4.2.6, and 4.3.0, validate_partitions only check...
CVE-2026-66074MEDIUM6RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, match_value/3...
CVE-2026-66072MEDIUM6RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, get_chunk_sel...
CVE-2026-66068MEDIUM5.6RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, ?LOG_DEBUG("s...
CVE-2026-66067MEDIUM6RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, The stream open handler calls only chec...
CVE-2026-96551MEDIUM4.3A vulnerability was determined in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Impacted is an unk...
CVE-2026-84724MEDIUM6.6An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The ...
CVE-2026-84721MEDIUM6.4A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification...
CVE-2026-84720MEDIUM6.5A flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode.ancestor_artifacts databa...
CVE-2026-84718MEDIUM4.3A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the ...
CVE-2026-84717MEDIUM5.3A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center web...
CVE-2026-84716MEDIUM6.6A flaw was found in the automation-controller instance install-bundle endpoint. When a System Administ...
CVE-2026-84713MEDIUM6.5A flaw was found in the automation-controller notification subsystem. Although NotificationTemplate.no...
CVE-2026-84712MEDIUM5.3A flaw was found in the automation-controller API. The unauthenticated health-check endpoint /api/v2/p...
CVE-2026-96548MEDIUM5.6A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects an unknown par...
CVE-2026-96545MEDIUM4.4An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that ca...
CVE-2026-95602MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploitin...
CVE-2026-95600MEDIUM5.3Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions.
CVE-2026-95592MEDIUM5.3Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions.
CVE-2026-95586MEDIUM6.5Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions.
CVE-2026-95530MEDIUM6.5Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions.
CVE-2026-95527MEDIUM6.5Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.
CVE-2026-95525MEDIUM6.5Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions.
CVE-2026-95524MEDIUM5.3Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now