2026 CVE Vulnerabilities

47,201 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-42862MEDIUM5Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass ...
CVE-2026-29170MEDIUM6.1A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4....
CVE-2026-11529MEDIUM6.3A vulnerability was determined in designcomputer mysql-mcp-server up to 0.2.2. The impacted element is the function read...
CVE-2026-25558MEDIUM4.8QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authent...
CVE-2026-11521MEDIUM6.3A security vulnerability has been detected in Mohammed-eid35 bank-management-system-springboot up to 7b9bcc65ad7df3db29a...
CVE-2026-11519MEDIUM6.3A security flaw has been discovered in SourceCodester Inventory System 1.0. Affected by this vulnerability is an unknown...
CVE-2026-11518MEDIUM4.3A vulnerability was identified in SourceCodester Inventory System 1.0. Affected is an unknown function of the file /user...
CVE-2026-11516MEDIUM5.5A vulnerability was found in UTT HiPER 2610G up to 3.0.0-171107. This affects the function strcpy of the file /goform/fo...
CVE-2026-9549MEDIUM4.8Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and ...
CVE-2026-8833MEDIUM5.4Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0...
CVE-2026-8078MEDIUM4.8Stored cross-site scripting in the global settings change log in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 v...
CVE-2026-7765MEDIUM5.3Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints ...
CVE-2026-7186MEDIUM5.4Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 version...
CVE-2026-11515MEDIUM5.5A vulnerability has been found in SourceCodester Barangay Resident Profiling and Information Management System 1.0. The ...
CVE-2026-11514MEDIUM6.3A flaw has been found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the...
CVE-2026-11513MEDIUM6.3A vulnerability was detected in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file...
CVE-2026-11512MEDIUM4.3A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This issue affects some unkno...
CVE-2026-3011MEDIUM6.4The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'su...
CVE-2026-11569MEDIUM5.4A flaw was found in Quay. The filedrop endpoint accepts any mime type without validation, allowing an authenticated user...
CVE-2026-11510MEDIUM6.3A security flaw has been discovered in CodeAstro Leave Management System 1.0. This affects an unknown part of the file /...
CVE-2026-11509MEDIUM6.3A vulnerability was identified in CodeAstro Leave Management System 1.0. Affected by this issue is some unknown function...
CVE-2026-11508MEDIUM6.3A vulnerability was determined in CodeAstro Leave Management System 1.0. Affected by this vulnerability is an unknown fu...
CVE-2026-11507MEDIUM6.3A vulnerability was found in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /admin/d...
CVE-2026-11506MEDIUM6.3A vulnerability has been found in CodeAstro Leave Management System 1.0. This impacts an unknown function of the file /a...
CVE-2026-11505MEDIUM5A flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now