2026 CVE Vulnerabilities

64,760 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-61834MEDIUM4.3scim-patch is a library for applying SCIM patch operations. Prior to 0.9.2, navigate() reads inherited properties and as...
CVE-2026-61413MEDIUM6.8Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Managemen...
CVE-2026-18179MEDIUM6.5IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions...
CVE-2026-84091MEDIUM5.3The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a...
CVE-2026-77112MEDIUM6.5Server-Side request forgery (SSRF) vulnerability in Global IT Informatics Technology Services Inc. Weoll allows Server S...
CVE-2026-96446MEDIUM4.2A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak. The issue occurs when the silent au...
CVE-2026-96445MEDIUM6.8A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue...
CVE-2026-80444MEDIUM5.4URL redirection to untrusted site ('open redirect') vulnerability in Abis Technology Ltd. Co. AVESİS allows Input Data M...
CVE-2026-73581MEDIUM6.5Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implement...
CVE-2026-96456MEDIUM6.3The Reachy Mini Bluetooth service asks a connecting device for a PIN before it will accept commands. The check protects ...
CVE-2026-90950MEDIUM5.3The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handle...
CVE-2026-87978MEDIUM5.3The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on one branch of its pay...
CVE-2026-87071MEDIUM5.3The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which metadata keys a form submission may supply...
CVE-2026-87070MEDIUM5.3The Forminator Forms WordPress plugin before 1.57.2.1 does not verify that a request came from a trusted proxy before pr...
CVE-2026-86612MEDIUM5.6The Ninja Tables WordPress plugin before 5.2.17 does not restrict shortcode expansion to administrator-authored table ro...
CVE-2026-86604MEDIUM4.8The GTranslate WordPress plugin before 5.0.1 does not remove shortcodes from the content of outgoing emails before expan...
CVE-2026-86601MEDIUM6.5The WP Recipe Maker WordPress plugin before 10.8.2 does not remove shortcodes from comment content before expanding it w...
CVE-2026-5696MEDIUM5.9Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability lies in the ‘group’ parameter of the ‘/admin/setti...
CVE-2026-96443MEDIUM6.5Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution...
CVE-2026-94251MEDIUM6.5A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resou...
CVE-2026-92001MEDIUM6.1Improper restriction of recursive entity references in DTDs ('XML entity expansion') vulnerability in Apache Sling XSS. ...
CVE-2026-91999MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. ...
CVE-2026-91928MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. ...
CVE-2026-91852MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. ...
CVE-2026-73192MEDIUM6.1An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when usin...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now