2026 CVE Vulnerabilities

64,760 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-96672MEDIUM6.4Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values refere...
CVE-2026-79306MEDIUM6.5CyberPanel v1.9.1 contains a path traversal vulnerability in the compress method exposed through the /filemanager/contro...
CVE-2026-79304MEDIUM6.5CyberPanel 1.9.1 contains a path traversal vulnerability in the readFileContents method of the /filemanager/controller e...
CVE-2026-6327MEDIUM4.3IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutra...
CVE-2026-3626MEDIUM5.3IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical ...
CVE-2026-19267MEDIUM6.2IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rul...
CVE-2026-19087MEDIUM4.4IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalatio...
CVE-2026-18505MEDIUM5.4IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter...
CVE-2026-18180MEDIUM6.5IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensi...
CVE-2026-96611MEDIUM6.9FFmpeg before 9.0 has a signed integer overflow in libavformat/mov.c. In mov_read_ispe(), uint32_t width/height values f...
CVE-2026-96600MEDIUM5.5Isotope eCommerce through 2.9.10 contains a blind SQL injection vulnerability in backend callbacks that interpolate requ...
CVE-2026-96599MEDIUM5.9Isotope eCommerce through 2.9.10 derives order identifiers from uniqid() instead of a cryptographically secure source, a...
CVE-2026-96276MEDIUM6.5If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak ...
CVE-2026-92419MEDIUM5.3WEBCON BPS is vulnerable to Insecure Direct Object Reference (IDOR) in the /api/vacations/{path} endpoint. The selectedP...
CVE-2026-92164MEDIUM6.5Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.6.0, HTTPSes...
CVE-2026-88974MEDIUM5.4WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjec...
CVE-2026-73858MEDIUM5.3Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. From 5.0.0 through 5.10.13, submitted...
CVE-2026-73589MEDIUM6.3Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Weak ...
CVE-2026-73587MEDIUM6.8Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validat...
CVE-2026-73586MEDIUM6.4Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Insufficient Session Expirat...
CVE-2026-71177MEDIUM5.4Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rend...
CVE-2026-63002MEDIUM4.8REDAXO is a PHP-based content management system. Prior to 5.21.2, redaxo/src/addons/mediapool/pages/sync.php inserts fil...
CVE-2026-63001MEDIUM4.8REDAXO is a PHP-based content management system. Prior to 5.21.2, the mediaIsInUse() handler in redaxo/src/addons/media_...
CVE-2026-63000MEDIUM6.4REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_api_install_package_update in redaxo/src/addons/in...
CVE-2026-62998MEDIUM4.3REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_list::getSortColumn() in redaxo/src/core/lib/list....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now