2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-16558MEDIUM5.4The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it...
CVE-2026-16535MEDIUM6.1The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a r...
CVE-2026-16282MEDIUM5.3The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against t...
CVE-2026-16269MEDIUM4.8The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthentica...
CVE-2026-18988MEDIUM6.4The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block a...
CVE-2026-49343MEDIUM5.9Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie...
CVE-2026-48122MEDIUM5.4Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP...
CVE-2026-48047MEDIUM5.9XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to ...
CVE-2026-47127MEDIUM6.5Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-UR...
CVE-2026-64676MEDIUM5.7Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In ...
CVE-2026-46405MEDIUM5.3OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth m...
CVE-2026-11743MEDIUM6.6The SF32LB MPI QSPI NOR flash driver (drivers/flash/flash_sf32lb_mpi_qspi_nor.c) validated the flash offset and length o...
CVE-2026-9031MEDIUM6.8An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied da...
CVE-2026-9030MEDIUM6.8A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool instruction han...
CVE-2026-71381MEDIUM4Adobe Genuine Software Integrity Service was affected by an Incorrect Authorization vulnerability that could result in a...
CVE-2026-69207MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in COR...
CVE-2026-59717MEDIUM4.3Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.6.1, the Andr...
CVE-2026-54338MEDIUM5.3JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid in...
CVE-2026-46358MEDIUM5.4OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functi...
CVE-2026-19246MEDIUM6.3A vulnerability has been found in HKUDS nanobot up to 0.2.1. This affects the function _download_image_data_url of the f...
CVE-2026-19244MEDIUM4.7A vulnerability was detected in HKUDS nanobot up to 0.2.1. The affected element is the function connect_mcp_servers of t...
CVE-2026-11425MEDIUM4.4Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that allo...
CVE-2026-71870MEDIUM4.8pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumpti...
CVE-2026-66151MEDIUM5.5SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the ...
CVE-2026-62293MEDIUM5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now