2026 CVE Vulnerabilities

45,066 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-12610MEDIUM6.4A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free v...
CVE-2026-45822MEDIUM6.6decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' produci...
CVE-2026-9576MEDIUM4.9The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting a...
CVE-2026-56809MEDIUM6.1Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cr...
CVE-2026-11581MEDIUM5.9The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's ca...
CVE-2026-8944MEDIUM4.3The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in v...
CVE-2026-12560MEDIUM4.4The Editorial Rating – Product Review & Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2026-12349MEDIUM5.3The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in ...
CVE-2026-11367MEDIUM6.5The PixMagix – WordPress Image Editor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, a...
CVE-2026-14160MEDIUM5.9Time-of-check time-of-use (TOCTOU) race condition vulnerability in Samsung Open Source Escargot allows Leveraging Race C...
CVE-2026-12114MEDIUM4.4The Team Members – Multi Language Supported Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2026-7656MEDIUM6.8The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_input) use...
CVE-2026-10648MEDIUM5.5mcumgr_serial_process_frag() in subsys/mgmt/mcumgr/transport/src/serial_util.c calls net_buf_reset() on the result of sm...
CVE-2026-57997MEDIUM5.4Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not exp...
CVE-2026-10647MEDIUM5.3The USB CDC-NCM device class (subsys/usb/device_next/class/usbd_cdc_ncm.c) ignores the return value of usbd_ep_enqueue()...
CVE-2026-55956MEDIUM6.5Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ig...
CVE-2026-55955MEDIUM6.5Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the ...
CVE-2026-50229MEDIUM6.1Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example ...
CVE-2026-54889MEDIUM5.1Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in leandrocp mdex allows cross-site scri...
CVE-2026-54888MEDIUM6.9Uncontrolled Recursion vulnerability in leandrocp mdex allows denial of service via deeply nested Markdown input. mdex ...
CVE-2026-53429MEDIUM6.9Missing Release of Memory after Effective Lifetime vulnerability in leandrocp mdex and mdex_native allows an attacker wh...
CVE-2026-43746MEDIUM6.5A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 a...
CVE-2026-43745MEDIUM6.5An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26....
CVE-2026-43743MEDIUM4.7A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS ...
CVE-2026-43742MEDIUM6.5A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now