2026 CVE Vulnerabilities

44,976 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-56149MEDIUM4.9Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce...
CVE-2026-56148MEDIUM6.5Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). ...
CVE-2026-49088MEDIUM4.4Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclosure. When the option...
CVE-2026-49087MEDIUM6.5Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A...
CVE-2026-34098MEDIUM4.8Guardian language-system fails to sanitize the id GET parameter before inserting it into HTML source and form action att...
CVE-2026-34097MEDIUM4.8Guardian language-system fails to sanitize the id GET parameter before inserting it into multiple HTML form action attri...
CVE-2026-34096MEDIUM4.8Guardian language-system fails to sanitize the name GET parameter before outputting it into an HTML input value attribut...
CVE-2026-27409MEDIUM5.3Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Configured Access Contr...
CVE-2026-13211MEDIUM4.3The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption ke...
CVE-2026-12480MEDIUM5.5Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an incomplete fix for CVE...
CVE-2026-8480MEDIUM4.3A vulnerability was discovered on Stormshield Network Security 4.3.0  to 4.3.41 (included), 4.4.0 to 4.8.15 (included) ,...
CVE-2026-58038MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-58037MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-58033MEDIUM6.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne...
CVE-2026-58032MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-58030MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-58029MEDIUM6.5Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiC...
CVE-2026-58028MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-58027MEDIUM6.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter. This vul...
CVE-2026-58026MEDIUM5.7Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne...
CVE-2026-58024MEDIUM5.7Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne...
CVE-2026-6686MEDIUM4.6FatFs R0.16 and earlier contains an uninitialized cluster exposure when f_lseek() extends files beyond EOF without zero-...
CVE-2026-6684MEDIUM4.6FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' contains an issue where an unbounded loop count derived f...
CVE-2026-6683MEDIUM4.6FatFs R0.16 and earlier contains a divide-by-zero in exFAT sync logic bug when crafted metadata causes n_fatent - 2 to b...
CVE-2026-6283MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Informa...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now