2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-17599MEDIUM6.9Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. Th...
CVE-2026-17598MEDIUM5.3Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when ...
CVE-2026-17597MEDIUM5.1Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification f...
CVE-2026-17596MEDIUM6.3Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:cre...
CVE-2026-17595MEDIUM5.3Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:select...
CVE-2026-66059MEDIUM5.3Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass expose...
CVE-2026-62996MEDIUM6.9Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From...
CVE-2026-62992MEDIUM6.9Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prio...
CVE-2026-48093MEDIUM6.5The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting (XSS) through the ex...
CVE-2026-19210MEDIUM6.3A vulnerability has been found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of...
CVE-2026-37171MEDIUM5.9A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one ...
CVE-2026-19206MEDIUM5.3A security flaw has been discovered in MZ Automation libiec61850 up to 1.6.1. This affects the function SVReceiver_stopT...
CVE-2026-16637MEDIUM6.5OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlis...
CVE-2026-66838MEDIUM5.9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgr...
CVE-2026-56794MEDIUM6.5Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A lo...
CVE-2026-48094MEDIUM5.3The ShareOpenly WordPress plugin prior to version 1.2.1 contains a Cross-Site Scripting vulnerability caused by the abse...
CVE-2026-54217MEDIUM5.3Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An attacker can send ...
CVE-2026-54216MEDIUM5.3Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) vulnerability. By ...
CVE-2026-54215MEDIUM5.3Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An atta...
CVE-2026-54214MEDIUM5.3Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL par...
CVE-2026-54207MEDIUM6.3Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, whi...
CVE-2026-54206MEDIUM6.3Tobit Laboratories AG TeamDavid's Webbox 's sending email, fax, SMS, etc. functionality accepts a @@INCLUDE command, wh...
CVE-2026-54205MEDIUM6.3Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname”...
CVE-2026-54201MEDIUM6.9Tobit Laboratories AG TeamDavid's Webbox does not enforce authentication or authorization checks when serving these lo...
CVE-2026-54199MEDIUM5.3Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the request body in the applic...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now