2026 CVE Vulnerabilities

45,152 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-12863MEDIUM5.1An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using...
CVE-2026-12862MEDIUM5.1Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be...
CVE-2026-12580MEDIUM5.4EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attack...
CVE-2026-54665MEDIUM5.3Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an...
CVE-2026-44911MEDIUM6.3Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clie...
CVE-2026-7859MEDIUM5.3The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX action...
CVE-2026-4110MEDIUM6.1The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outp...
CVE-2026-10530MEDIUM5.3The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account v...
CVE-2026-11748MEDIUM6.9A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstAct...
CVE-2026-12821MEDIUM6.3A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown function of the file...
CVE-2026-12815MEDIUM6.3A vulnerability has been found in coollabsio coolify 4.0.0. Impacted is an unknown function of the component Image Name ...
CVE-2026-12814MEDIUM6.3A flaw has been found in Comfast CF-WR631AX V3 up to 2.7.0.8. This issue affects the function system of the file /cgi-bi...
CVE-2026-12813MEDIUM6.3A vulnerability was detected in activepieces up to 0.83.0. This vulnerability affects the function handleUrlFile in the ...
CVE-2026-12811MEDIUM4.3A weakness has been identified in kortix-ai suna up to 0.8.38. Affected by this issue is the function router.replace/rou...
CVE-2026-12810MEDIUM6.3A security flaw has been discovered in Edimax BR-6478AC V2 1.23. Affected by this vulnerability is the function mp of th...
CVE-2026-12809MEDIUM6.3A vulnerability was identified in Edimax BR-6478AC V2 1.23. Affected is the function wiz_5in1_redirect of the file /gofo...
CVE-2026-12808MEDIUM6.3A vulnerability was determined in Edimax BR-6478AC V2 1.23. This impacts the function stainfo of the file /goform/stainf...
CVE-2026-12807MEDIUM6.3A vulnerability was found in Edimax BR-6478AC V2 1.23. This affects the function setWAN of the file /goform/setWAN of th...
CVE-2026-12805MEDIUM6.3A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element is the function XMLNode::parseFile in the library...
CVE-2026-12804MEDIUM4.3A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-p...
CVE-2026-56412MEDIUM5.9libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking ...
CVE-2026-56411MEDIUM6.9xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
CVE-2026-56410MEDIUM6.9xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
CVE-2026-56409MEDIUM6.5xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
CVE-2026-56408MEDIUM6.9libexpat before 2.8.2 has an integer overflow in copyString.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now