2026 CVE Vulnerabilities

45,066 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-13437MEDIUM6.5Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 a...
CVE-2026-57341MEDIUM6.5Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce ...
CVE-2026-57340MEDIUM6.5Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.
CVE-2026-57339MEDIUM6.5Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.
CVE-2026-57335MEDIUM6.5Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions.
CVE-2026-57334MEDIUM6.5Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.
CVE-2026-57330MEDIUM6.5Subscriber Cross Site Scripting (XSS) in MasterStudy LMS <= 3.7.27 versions.
CVE-2026-57329MEDIUM6.5Subscriber Cross Site Scripting (XSS) in WooCommerce Designer Pro <= 1.9.34 versions.
CVE-2026-57328MEDIUM6.5Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.
CVE-2026-57327MEDIUM6.3Subscriber Broken Access Control in MainWP <= 6.1.1 versions.
CVE-2026-57326MEDIUM6.1Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.
CVE-2026-46406MEDIUM6.1Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a ha...
CVE-2026-13579MEDIUM6.3A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this issue is some unknown fu...
CVE-2026-13578MEDIUM6.3A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an...
CVE-2026-13572MEDIUM6.3A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown functi...
CVE-2026-13571MEDIUM5.5A flaw has been found in SourceCodester Simple Food Ordering System 1.0. The affected element is an unknown function of ...
CVE-2026-56457MEDIUM4.3HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This...
CVE-2026-13569MEDIUM4.7A security vulnerability has been detected in weng-xianhu EyouCMS up to 1.7.1. This issue affects some unknown processin...
CVE-2026-13567MEDIUM4.3A security flaw has been discovered in code-projects Online Music Site 1.0. This affects an unknown part of the file /Fr...
CVE-2026-12616MEDIUM6.9The /v1/upload/sbom endpoint extracts the iss claim from the attacker-supplied JWT with signature verification disabled,...
CVE-2026-41991MEDIUM4.7GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp util...
CVE-2026-13561MEDIUM6.3A vulnerability was detected in Edimax EW-7478APC 1.04. The impacted element is the function formiNICbasic of the file /...
CVE-2026-13560MEDIUM6.3A security vulnerability has been detected in Edimax EW-7478APC 1.04. The affected element is the function formAccept of...
CVE-2026-13601MEDIUM6.5A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. ...
CVE-2026-13557MEDIUM4.3A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. This vulnerability affects unknown co...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now