2026 CVE Vulnerabilities

45,091 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-57914MEDIUM6.5By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow ...
CVE-2026-57620MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclu...
CVE-2026-57473MEDIUM5.8A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911)...
CVE-2026-6658MEDIUM5.4A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Scripting (XSS) via unsanitized `text/vnd....
CVE-2026-1869MEDIUM6.5The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom U...
CVE-2026-8380MEDIUM6.5The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post...
CVE-2026-8661MEDIUM4.8Server-Side Request Forgery in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin on Linux in versions ...
CVE-2026-50745MEDIUM6.1A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script w...
CVE-2026-50744MEDIUM4.3A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login me...
CVE-2026-50742MEDIUM5.4A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revi...
CVE-2026-50740MEDIUM5.4A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and ea...
CVE-2026-50739MEDIUM4.3A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation o...
CVE-2026-48934MEDIUM4.3A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability ...
CVE-2026-48928MEDIUM5.4A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulne...
CVE-2026-48618MEDIUM6.5A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth ...
CVE-2026-13226MEDIUM6.5The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection ...
CVE-2026-43920MEDIUM6.9FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patch...
CVE-2026-13318MEDIUM6.4A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-...
CVE-2026-13218MEDIUM4.2A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function writes data to a laun...
CVE-2026-13083MEDIUM6.9A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper es...
CVE-2026-12993MEDIUM6.5A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but d...
CVE-2026-40941MEDIUM6.5Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import sign...
CVE-2026-40084MEDIUM6.5Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Tra...
CVE-2026-40082MEDIUM5.4Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regen...
CVE-2026-40080MEDIUM6.1Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Open Red...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now