2026 CVE Vulnerabilities
45,152 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12863 | MEDIUM | 5.1 | 0.2% | Jun 22, 2026 | An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using... |
| CVE-2026-12862 | MEDIUM | 5.1 | 0.2% | Jun 22, 2026 | Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be... |
| CVE-2026-12580 | MEDIUM | 5.4 | 0.2% | Jun 22, 2026 | EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attack... |
| CVE-2026-54665 | MEDIUM | 5.3 | 0.3% | Jun 22, 2026 | Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an... |
| CVE-2026-44911 | MEDIUM | 6.3 | 0.3% | Jun 22, 2026 | Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clie... |
| CVE-2026-7859 | MEDIUM | 5.3 | 0.1% | Jun 22, 2026 | The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX action... |
| CVE-2026-4110 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outp... |
| CVE-2026-10530 | MEDIUM | 5.3 | 0.1% | Jun 22, 2026 | The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account v... |
| CVE-2026-11748 | MEDIUM | 6.9 | 0.4% | Jun 22, 2026 | A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstAct... |
| CVE-2026-12821 | MEDIUM | 6.3 | 0.3% | Jun 22, 2026 | A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown function of the file... |
| CVE-2026-12815 | MEDIUM | 6.3 | 1.2% | Jun 22, 2026 | A vulnerability has been found in coollabsio coolify 4.0.0. Impacted is an unknown function of the component Image Name ... |
| CVE-2026-12814 | MEDIUM | 6.3 | 1.2% | Jun 21, 2026 | A flaw has been found in Comfast CF-WR631AX V3 up to 2.7.0.8. This issue affects the function system of the file /cgi-bi... |
| CVE-2026-12813 | MEDIUM | 6.3 | 0.2% | Jun 21, 2026 | A vulnerability was detected in activepieces up to 0.83.0. This vulnerability affects the function handleUrlFile in the ... |
| CVE-2026-12811 | MEDIUM | 4.3 | 0.3% | Jun 21, 2026 | A weakness has been identified in kortix-ai suna up to 0.8.38. Affected by this issue is the function router.replace/rou... |
| CVE-2026-12810 | MEDIUM | 6.3 | 1.2% | Jun 21, 2026 | A security flaw has been discovered in Edimax BR-6478AC V2 1.23. Affected by this vulnerability is the function mp of th... |
| CVE-2026-12809 | MEDIUM | 6.3 | 1.2% | Jun 21, 2026 | A vulnerability was identified in Edimax BR-6478AC V2 1.23. Affected is the function wiz_5in1_redirect of the file /gofo... |
| CVE-2026-12808 | MEDIUM | 6.3 | 1.2% | Jun 21, 2026 | A vulnerability was determined in Edimax BR-6478AC V2 1.23. This impacts the function stainfo of the file /goform/stainf... |
| CVE-2026-12807 | MEDIUM | 6.3 | 1.2% | Jun 21, 2026 | A vulnerability was found in Edimax BR-6478AC V2 1.23. This affects the function setWAN of the file /goform/setWAN of th... |
| CVE-2026-12805 | MEDIUM | 6.3 | 0.3% | Jun 21, 2026 | A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element is the function XMLNode::parseFile in the library... |
| CVE-2026-12804 | MEDIUM | 4.3 | 0.3% | Jun 21, 2026 | A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-p... |
| CVE-2026-56412 | MEDIUM | 5.9 | 0.1% | Jun 21, 2026 | libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking ... |
| CVE-2026-56411 | MEDIUM | 6.9 | 0.1% | Jun 21, 2026 | xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations. |
| CVE-2026-56410 | MEDIUM | 6.9 | 0.1% | Jun 21, 2026 | xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId. |
| CVE-2026-56409 | MEDIUM | 6.5 | 0.1% | Jun 21, 2026 | xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used. |
| CVE-2026-56408 | MEDIUM | 6.9 | 0.1% | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in copyString. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now