2026 CVE Vulnerabilities

45,307 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-20220MEDIUM6.3A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenti...
CVE-2026-1288MEDIUM5.5A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL...
CVE-2026-12515MEDIUM4.3A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization chec...
CVE-2026-55748MEDIUM6OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name ...
CVE-2026-48142MEDIUM6.3NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or p...
CVE-2026-48117MEDIUM6.8DroneAware is a drone detection platform. The centralized DroneAware server backing droneaware.io was vulnerable to an a...
CVE-2026-40641MEDIUM4.8Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Use of a Broken or Risky Cryptographic Algorithm vuln...
CVE-2026-35162MEDIUM6.5Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileg...
CVE-2026-12528MEDIUM5.4A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Acce...
CVE-2026-11311MEDIUM6.5When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX...
CVE-2026-10850MEDIUM5.4Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when cre...
CVE-2026-9591MEDIUM6.9Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthent...
CVE-2026-54817MEDIUM6.5Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recover...
CVE-2026-52716MEDIUM6.5Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.
CVE-2026-8607MEDIUM6.4The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress ...
CVE-2026-8494MEDIUM6.4The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admi...
CVE-2026-8383MEDIUM5.3The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `e...
CVE-2026-7850MEDIUM5.9The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting t...
CVE-2026-54196MEDIUM6.8Subscriber Privilege Escalation in JetFormBuilder <= 3.6.1 versions.
CVE-2026-49072MEDIUM6.5Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions.
CVE-2026-49071MEDIUM6.5Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions.
CVE-2026-48783MEDIUM4.8Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accept...
CVE-2026-48782MEDIUM6.8Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 t...
CVE-2026-47340MEDIUM6.5Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. ...
CVE-2026-47277MEDIUM6.5Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos fro...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now