2026 CVE Vulnerabilities

45,891 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-49496MEDIUM6.9Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator ...
CVE-2026-49495MEDIUM6.7Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.parseTrie() that lacks...
CVE-2026-11853MEDIUM6.5Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages...
CVE-2026-11852MEDIUM6.5Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debus...
CVE-2026-9019MEDIUM6.4The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderCol...
CVE-2026-8853MEDIUM4.4The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all version...
CVE-2026-8613MEDIUM6.4The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widge...
CVE-2026-29115MEDIUM6.9A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially c...
CVE-2026-11815MEDIUM5.3An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could pote...
CVE-2026-24720MEDIUM6.5An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a r...
CVE-2026-24717MEDIUM6.5A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker ...
CVE-2026-22899MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user a...
CVE-2026-46532MEDIUM4.6ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.3, and 6.0...
CVE-2026-45329MEDIUM6.5ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secu...
CVE-2026-45160MEDIUM6.5ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0...
CVE-2026-46546MEDIUM5.4Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version ...
CVE-2026-53675MEDIUM5.3BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any aut...
CVE-2026-46543MEDIUM5.3Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to...
CVE-2026-46542MEDIUM4.3Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to...
CVE-2026-46540MEDIUM6.5Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to...
CVE-2026-46539MEDIUM5.9Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to...
CVE-2026-46411MEDIUM6.5FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.2, authorized clients have t...
CVE-2026-44505MEDIUM5.3Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. network-...
CVE-2026-41837MEDIUM5.3Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and...
CVE-2026-41730MEDIUM5.3Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persist...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now