2026 CVE Vulnerabilities

46,876 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-41008MEDIUM6.1Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parame...
CVE-2026-41003MEDIUM5.4An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generat...
CVE-2026-40991MEDIUM5.9When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an ...
CVE-2026-9751MEDIUM6.8The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mon...
CVE-2026-9742MEDIUM5.9When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of th...
CVE-2026-9735MEDIUM6.8MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. W...
CVE-2026-46433MEDIUM6.5lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips ...
CVE-2026-47905MEDIUM6.2CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu...
CVE-2026-47904MEDIUM6.2CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu...
CVE-2026-47903MEDIUM6.2CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation v...
CVE-2026-47902MEDIUM6.2CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu...
CVE-2026-34657MEDIUM5.5CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Limitation of a Pa...
CVE-2026-34417MEDIUM6.1OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbit...
CVE-2026-25860MEDIUM6.1OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that al...
CVE-2026-47961MEDIUM5.5Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that ...
CVE-2026-47933MEDIUM4.8ColdFusion versions 2023.19, 2025.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that c...
CVE-2026-47926MEDIUM5.5Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that ...
CVE-2026-47925MEDIUM5.5Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Integer Overflow or Wraparound vulnera...
CVE-2026-47924MEDIUM5.5Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could...
CVE-2026-47923MEDIUM5.5Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that ...
CVE-2026-34416MEDIUM6.1OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbit...
CVE-2026-25557MEDIUM5.4Evoluted PHP Directory Listing Script through 4.0.5 contains a reflected cross-site scripting vulnerability in index.php...
CVE-2026-47910MEDIUM6.3Dreamweaver Desktop versions 21.7 and earlier are affected by an Incorrect Authorization vulnerability that could lead t...
CVE-2026-47909MEDIUM6.3Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Input Validation vulnerability that could lead...
CVE-2026-47106MEDIUM5.4Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a stored cross-site scripting vulnerabili...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now