2026 CVE Vulnerabilities

46,944 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-34692MEDIUM5.4Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting ...
CVE-2026-33113MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-28301MEDIUM4.8A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to an unintended websit...
CVE-2026-0420MEDIUM5.9An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which co...
CVE-2026-0418MEDIUM4.5Insufficient configuration management in the listed devices allows authenticated administrators connected to the local n...
CVE-2026-0417MEDIUM4.5Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected ...
CVE-2026-0416MEDIUM4.5An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated admini...
CVE-2026-0415MEDIUM4.5Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t...
CVE-2026-0414MEDIUM4.5Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t...
CVE-2026-0413MEDIUM4.5A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated a...
CVE-2026-0412MEDIUM4.5Insufficient input validation vulnerability in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in ...
CVE-2026-0410MEDIUM4.5Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorize...
CVE-2026-0409MEDIUM6.4A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the rout...
CVE-2026-8045MEDIUM6.5CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosu...
CVE-2026-49938MEDIUM6.5A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, Fo...
CVE-2026-52905MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: disallow non-power of two min_region...
CVE-2026-52904MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix nvkm_device leak on aperture remov...
CVE-2026-49762MEDIUM5.1Uncontrolled Resource Consumption vulnerability in the Elixir standard library's Version module allows an attacker who c...
CVE-2026-47901MEDIUM4.6Logseq is vulnerable to a sandbox escape flaw where plugins running in sandboxed iframes can inject arbitrary HTML attri...
CVE-2026-47900MEDIUM4.6Logseq is vulnerable to a stored cross-site scripting (XSS). A malicious plugin can include a JavaScript payload in the ...
CVE-2026-46329MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: erofs: handle end of filesystem properly for file-b...
CVE-2026-11793MEDIUM4.9A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-co...
CVE-2026-11790MEDIUM4.9A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on t...
CVE-2026-11789MEDIUM6.5A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when comp...
CVE-2026-11787MEDIUM6.3A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now