2026 CVE Vulnerabilities

47,534 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-6239MEDIUM6.8A stack‑based buffer overflow vulnerability exists in Tapo C520WS v2 in the ONVIF CreateUsers service, where the device ...
CVE-2026-10038MEDIUM4.3The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vul...
CVE-2026-7523MEDIUM4.3The Alba Board plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. T...
CVE-2026-45409MEDIUM5.3Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in ...
CVE-2026-46401MEDIUM5.3HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.0 suffer from an improper se...
CVE-2026-46397MEDIUM6.5HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an Authenticated Local Fil...
CVE-2026-46357MEDIUM6.5HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the HAX CMS NodeJS applica...
CVE-2026-45778MEDIUM5.4OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, an authenticated attac...
CVE-2026-45776MEDIUM4.3OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, a flaw in Open XDMoD's...
CVE-2026-25624MEDIUM4.8An administrative cross-site scripting (XSS) vulnerability exists in the web user interface dashboard layout of Arista E...
CVE-2026-46390MEDIUM6.9HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 2.0.0 and prior to version 26.0...
CVE-2026-11341MEDIUM6.3A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boaf...
CVE-2026-8714MEDIUM6.5A denial-of-service vulnerability exists in the RTSP server component of TP-Link Tapo C520WS v2 due to improper handling...
CVE-2026-7473MEDIUM6.9On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LA...
CVE-2026-48112MEDIUM6.57-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain a heap out-of-bounds read in...
CVE-2026-48104MEDIUM4.27-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain an uninitialized heap read i...
CVE-2026-11337MEDIUM4.3A vulnerability was found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e...
CVE-2026-48102MEDIUM4.37-Zip is a file archiver with a high compression ratio. Versions 9.11 through 26.00 contain a heap out-of-bounds read of...
CVE-2026-48101MEDIUM6.57-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An uninitialized memory d...
CVE-2026-11336MEDIUM6.3A vulnerability has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a388529...
CVE-2026-38579MEDIUM6.1Multiple reflected Cross-Site Scripting (XSS) vulnerabilities in damasac thaipalliative_lte through version 3.0 allow re...
CVE-2026-37737MEDIUM6.5sanic-cors version 2.2.0 and prior contains an improper regular expression in the try_match() function in sanic_cors/cor...
CVE-2026-11335MEDIUM6.3A flaw has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae...
CVE-2026-11333MEDIUM6.3A security vulnerability has been detected in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a...
CVE-2026-50235MEDIUM6.1Lyrion Music Server 9.2.0 contains a reflected cross-site scripting vulnerability in advanced search parameters that fai...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now