2026 CVE Vulnerabilities

45,091 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-55892MEDIUM5.5Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a ...
CVE-2026-4522MEDIUM6.7Missing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Intercepti...
CVE-2026-48946MEDIUM6.3The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php ma...
CVE-2026-48945MEDIUM5.3The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries/<id>/`, and only re...
CVE-2026-48944MEDIUM6.5The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SI...
CVE-2026-48943MEDIUM6.5K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by inc...
CVE-2026-48942MEDIUM6.1K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both...
CVE-2026-48941MEDIUM6.5The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to ad...
CVE-2026-6432MEDIUM5.3Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage.
CVE-2026-57587MEDIUM5.3A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a...
CVE-2026-57536MEDIUM6.3Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a success...
CVE-2026-57437MEDIUM5.3Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::XPath...
CVE-2026-57436MEDIUM5.3Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::Docum...
CVE-2026-49319MEDIUM6.9Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0 manufactured by ALPS ALPINE CO., L...
CVE-2026-13225MEDIUM5.3Malicious HTML content could be injected into the email address of an order, which pretix showed without sanitization o...
CVE-2026-13223MEDIUM6.3Our payment integration with Computop-based payment methods did not properly validate payment status responses. An atta...
CVE-2026-13222MEDIUM6.3Our payment integration with Oppwa-based payment methods did not properly validate payment status responses. An attacke...
CVE-2026-57619MEDIUM6.5Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.
CVE-2026-57429MEDIUM6.5Contributor Broken Access Control in Slim SEO <= 4.6.2 versions.
CVE-2026-56050MEDIUM6.5Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access ...
CVE-2026-56023MEDIUM5.4Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.
CVE-2026-56013MEDIUM6.5Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.
CVE-2026-52690MEDIUM5.9Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of D...
CVE-2026-4526MEDIUM6.5In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logi...
CVE-2026-47154MEDIUM6.5In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now