2026 CVE Vulnerabilities

45,829 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-45560MEDIUM6.1Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, wr...
CVE-2026-45559MEDIUM4.9Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ge...
CVE-2026-11884MEDIUM6.5A heap buffer overflow flaw was found in 389 Directory Server. When serializing objectclass definitions, the oc_superior...
CVE-2026-53442MEDIUM5.3Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before stor...
CVE-2026-53441MEDIUM5.4Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-prov...
CVE-2026-53440MEDIUM4.3Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet...
CVE-2026-53439MEDIUM4.3Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permis...
CVE-2026-53438MEDIUM4.3A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers with Item/Cancel permi...
CVE-2026-53437MEDIUM4.3Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately...
CVE-2026-53436MEDIUM4.3Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately...
CVE-2026-52759MEDIUM6.7Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary parser that allows at...
CVE-2026-52757MEDIUM4.6Ghidra before 12.1 contains a heap-use-after-free vulnerability in the decompiler's HighVariable::merge() function durin...
CVE-2026-52756MEDIUM6.5Ghidra before 12.2 contains an unauthenticated path traversal vulnerability in the IsfServer that accepts TCP connection...
CVE-2026-52753MEDIUM6.7Ghidra before 12.0.3 contains an out-of-memory vulnerability in the rust_demangle function that allocates unbounded outp...
CVE-2026-49497MEDIUM4.6Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames ...
CVE-2026-49496MEDIUM6.9Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator ...
CVE-2026-49495MEDIUM6.7Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.parseTrie() that lacks...
CVE-2026-11853MEDIUM6.5Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages...
CVE-2026-11852MEDIUM6.5Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debus...
CVE-2026-9019MEDIUM6.4The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderCol...
CVE-2026-8853MEDIUM4.4The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all version...
CVE-2026-8613MEDIUM6.4The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widge...
CVE-2026-29115MEDIUM6.9A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially c...
CVE-2026-11815MEDIUM5.3An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could pote...
CVE-2026-24720MEDIUM6.5An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a r...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now