2026 CVE Vulnerabilities

47,770 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-35718MEDIUM6.5A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allow...
CVE-2026-35716MEDIUM6.3A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authe...
CVE-2026-34460MEDIUM5.4NamelessMC is website software for Minecraft servers. In versions 2.2.4 and prior, the OAuth callback handling does not ...
CVE-2026-7313MEDIUM4.9CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 ...
CVE-2026-49782MEDIUM5.4Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Acce...
CVE-2026-43965MEDIUM5.6Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/pa...
CVE-2026-42795MEDIUM5.1Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in th...
CVE-2026-41918MEDIUM5.9A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applicatio...
CVE-2026-35717MEDIUM6.3A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows auth...
CVE-2026-32685MEDIUM4.6Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write...
CVE-2026-32250MEDIUM4.3NamelessMC is website software for Minecraft servers. A Reflected Cross-Site Scripting (XSS) vulnerability was discovere...
CVE-2026-28116MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emilia Projects Pr...
CVE-2026-27351MEDIUM5.4Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploiting Incorrectly Configured Access Control ...
CVE-2026-8993MEDIUM6.5D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Applicatio...
CVE-2026-5191MEDIUM5.4The Tiled Gallery Carousel Without JetPack plugin for WordPress is vulnerable to stored cross-site scripting via the 'da...
CVE-2026-46718MEDIUM6.5Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite. Thi...
CVE-2026-41115MEDIUM4.3An improper authorization vulnerability has been identified in Apache Kafka. The implementation of the CONSUMER_GROUP_D...
CVE-2026-34907MEDIUM5.1Wirtualna Uczelnia is vulnerable to Reflected Cross‑Site Scripting (XSS) due to insecure handling of the locale paramete...
CVE-2026-10549MEDIUM5.3LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker with valid LDAP crede...
CVE-2026-9730MEDIUM4.3The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to...
CVE-2026-9723MEDIUM4.3The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2026-9722MEDIUM4.3The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1....
CVE-2026-9599MEDIUM4.3The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2026-9234MEDIUM4.3The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and inc...
CVE-2026-8885MEDIUM6.4The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'callo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now