2026 CVE Vulnerabilities

46,946 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-46329MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: erofs: handle end of filesystem properly for file-b...
CVE-2026-11793MEDIUM4.9A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-co...
CVE-2026-11790MEDIUM4.9A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on t...
CVE-2026-11789MEDIUM6.5A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when comp...
CVE-2026-11787MEDIUM6.3A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without ...
CVE-2026-11786MEDIUM6.5A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute ...
CVE-2026-11785MEDIUM4.3A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial st...
CVE-2026-46318MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Revert "mm/hugetlbfs: update hugetlbfs to use mmap_...
CVE-2026-49740MEDIUM6.3TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP payloads without in...
CVE-2026-47352MEDIUM5.3Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission...
CVE-2026-47351MEDIUM5.3Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission ch...
CVE-2026-47350MEDIUM5.3Backend users were able to move records to a different page without having edit permissions on the source page. This iss...
CVE-2026-47349MEDIUM5.3Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they w...
CVE-2026-47348MEDIUM5.1Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in...
CVE-2026-47347MEDIUM5.3Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks ...
CVE-2026-52902MEDIUM4.7A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize ...
CVE-2026-4058MEDIUM4.3The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP...
CVE-2026-46747MEDIUM5.3A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application does not p...
CVE-2026-8677MEDIUM6.4The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored...
CVE-2026-8599MEDIUM6.4The MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable ...
CVE-2026-7542MEDIUM6.5The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions 7.0 to 7.0.10. ...
CVE-2026-6899MEDIUM5.6Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in th...
CVE-2026-49818MEDIUM6.5The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a c...
CVE-2026-46315MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: clear waitid info before copying i...
CVE-2026-34905MEDIUM6.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache An...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now