2026 CVE Vulnerabilities

42,999 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-19073MEDIUM5.3The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one o...
CVE-2026-19052MEDIUM4.3The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX ac...
CVE-2026-19050MEDIUM6.4The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the ca...
CVE-2026-18962MEDIUM4.3The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload int...
CVE-2026-18943MEDIUM6.5The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allow...
CVE-2026-12235MEDIUM6.3The Linkable Loadable Extensions (llext) subsystem mis-handles PLT/RELA relocation entries when linking a relocatable (p...
CVE-2026-12233MEDIUM5.9The PSA Protected Storage credential backend (subsys/net/lib/tls_credentials/tls_credentials_trusted.c) declared its cre...
CVE-2026-12232MEDIUM6.1The Intel ALH digital-audio-interface driver function dai_alh_get_properties() in drivers/dai/intel/alh/alh.c used a cal...
CVE-2026-9318MEDIUM5.4tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows...
CVE-2026-19588MEDIUM6.5Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.
CVE-2026-19587MEDIUM6.5Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.
CVE-2026-64927MEDIUM6.4A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissio...
CVE-2026-73250MEDIUM5.4Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the Notepad++ Windows 11 x64 and ARM64 installer...
CVE-2026-73245MEDIUM6.5Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/appli...
CVE-2026-66340MEDIUM6.9The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout ...
CVE-2026-64934MEDIUM5.3The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, witho...
CVE-2026-66832MEDIUM6.9When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is app...
CVE-2026-66148MEDIUM6.3An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.10...
CVE-2026-63134MEDIUM5.4Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction w...
CVE-2026-63133MEDIUM6.5Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives...
CVE-2026-48762MEDIUM5.4TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a u...
CVE-2026-29035MEDIUM6.5CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that...
CVE-2026-19579MEDIUM5.4Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request ...
CVE-2026-19550MEDIUM4.3A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rath...
CVE-2026-73282MEDIUM4.8In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now