2026 CVE Vulnerabilities

47,798 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-10581MEDIUM6.3A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the function base64_decode of the file /plus/...
CVE-2026-3871MEDIUM6.5A buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through ...
CVE-2026-3870MEDIUM6.5A buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.1...
CVE-2026-3722MEDIUM6.4The Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) plugin for WordPress...
CVE-2026-10568MEDIUM6.3A vulnerability was detected in itsourcecode Fees Management System 1.0. Affected is an unknown function of the file /ma...
CVE-2026-10566MEDIUM5.3A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct...
CVE-2026-10510MEDIUM6.1Cross-Site Scripting (XSS) in GeniexWebView component in Transsion AI Assistant Lifestyle application (com.transsion.aia...
CVE-2026-10100MEDIUM4.4The Simple Custom Login Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the color settings fi...
CVE-2026-10559MEDIUM6.3A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is an unknown function of the...
CVE-2026-10558MEDIUM6.3A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is an unknown function of the file...
CVE-2026-10550MEDIUM6.3A weakness has been identified in elunez eladmin up to 2.7. This vulnerability affects unknown code of the file App.java...
CVE-2026-10548MEDIUM5.3A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.23. This affects the function _sync_anthro...
CVE-2026-9050MEDIUM4.3The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7.0.14 is vulnerable to unauthorized modif...
CVE-2026-9048MEDIUM4.3The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 7.0.0 - 7.0.14, v...
CVE-2026-10302MEDIUM6.3A flaw has been found in itsourcecode Fees Management System 1.0. The impacted element is an unknown function of the fil...
CVE-2026-10301MEDIUM4.3A vulnerability was detected in itsourcecode Fees Management System 1.0. The affected element is an unknown function of ...
CVE-2026-28511MEDIUM4.3eLabFTW is an open source electronic lab notebook. Prior to version 5.4.2, in certain cases, an authenticated user perfo...
CVE-2026-24761MEDIUM4.3Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerabil...
CVE-2026-24756MEDIUM4.3Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerabil...
CVE-2026-24755MEDIUM5.4Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerabil...
CVE-2026-24754MEDIUM5.4Kiteworks is a private data network (PDN). Prior to version 9.3.0, a stored XSS vulnerability in Kiteworks Secure Data F...
CVE-2026-24753MEDIUM6.5Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerabil...
CVE-2026-10297MEDIUM6.3A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown part of the file /man...
CVE-2026-10296MEDIUM6.3A vulnerability was determined in itsourcecode Fees Management System 1.0. Affected by this issue is some unknown functi...
CVE-2026-28581MEDIUM4In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now