2026 CVE Vulnerabilities

43,246 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-63623MEDIUM5.5A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were tempora...
CVE-2026-56619MEDIUM5.4HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and out...
CVE-2026-12624MEDIUM4.3Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a tra...
CVE-2026-72726MEDIUM6.5Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated u...
CVE-2026-72725MEDIUM5.4Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previo...
CVE-2026-72724MEDIUM4.3Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, plugins/chat/lib/c...
CVE-2026-72723MEDIUM5.3Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, SiteSerializer.ano...
CVE-2026-72722MEDIUM4.3Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, TopicLink.extract_...
CVE-2026-72721MEDIUM5.3Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Onebox::DomainChec...
CVE-2026-72720MEDIUM6.4Discourse is an open-source discussion platform. Prior to 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, Discourse...
CVE-2026-72719MEDIUM6.7Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transf...
CVE-2026-56620MEDIUM4.3HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error repor...
CVE-2026-72761MEDIUM6.9The webhook URL validator in `website/notifications/webhooks.py` uses `ip.is_global` to reject non-public addresses afte...
CVE-2026-72760MEDIUM5.3Affected versions of MISP cti-transmute disclose users' email addresses through the account following-list endpoint. Whe...
CVE-2026-72759MEDIUM6.9In affected versions of MISP cti-transmute, the conversion-history details endpoint performs an incomplete authorization...
CVE-2026-72751MEDIUM5.1CTI-Transmute is affected by a stored cross-site scripting (XSS) vulnerability in the conversion graph used to visualise...
CVE-2026-71959MEDIUM5.8Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /c...
CVE-2026-63105MEDIUM5.4ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated custome...
CVE-2026-59112MEDIUM4.4Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability ...
CVE-2026-18478MEDIUM5.1Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrar...
CVE-2026-16742MEDIUM6.7systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed...
CVE-2026-15060MEDIUM4.7When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running o...
CVE-2026-15059MEDIUM5.5Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traver...
CVE-2026-6373MEDIUM6.5Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allow...
CVE-2026-19278MEDIUM6.8A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now