2026 CVE Vulnerabilities

68,165 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15650MEDIUM6.4The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2026-14855MEDIUM6.4The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all ...
CVE-2026-93456HIGH8.2django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing ...
CVE-2026-93455MEDIUM6.5django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff acc...
CVE-2026-93331HIGH7.3A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file ...
CVE-2026-93314MEDIUM6.3A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of t...
CVE-2026-93313MEDIUM6.3A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTabl...
CVE-2026-82985MEDIUM6.5The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolder...
CVE-2026-82982MEDIUM4.3The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing ...
CVE-2026-82980MEDIUM6.3Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The D...
CVE-2026-77170MEDIUM4.3The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without va...
CVE-2026-77169MEDIUM6.5A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed...
CVE-2026-77164MEDIUM6.2Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote insta...
CVE-2026-68493LOW3.1After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships ...
CVE-2026-93312MEDIUM4.3A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/J...
CVE-2026-93311MEDIUM4.3A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFun...
CVE-2026-93310MEDIUM5.3A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collect...
CVE-2026-79954HIGH8.7NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiv...
CVE-2026-93454MEDIUM5.4Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plu...
CVE-2026-93453HIGH8.3SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing u...
CVE-2026-93452HIGH7.5snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that wr...
CVE-2026-93451MEDIUM6.5snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allo...
CVE-2026-93450HIGH7.5go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serializatio...
CVE-2026-93309MEDIUM4.3A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of t...
CVE-2026-93308MEDIUM4.3A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now