2026 CVE Vulnerabilities

48,012 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-41159MEDIUM5.3Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 ...
CVE-2026-41150MEDIUM5.3Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 ...
CVE-2026-49325MEDIUM4.6Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 ...
CVE-2026-49316MEDIUM4.6Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allow...
CVE-2026-47696MEDIUM4.3WWBN AVideo is an open source video platform. In 29.0 and earlier, plugin/AuthorizeNet/processPayment.json.php credits t...
CVE-2026-47694MEDIUM5.4WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores category descriptions from user input a...
CVE-2026-46337MEDIUM5.3WWBN AVideo is an open source video platform. In 29.0 and earlier, an unauthenticated remote attacker can read arbitrary...
CVE-2026-45731MEDIUM4.9WWBN AVideo is an open source video platform. In 29.0 and earlier, view/update.php reads $_POST['updateFile'] as a relat...
CVE-2026-45620MEDIUM5.3WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or...
CVE-2026-45619MEDIUM6.5WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and o...
CVE-2026-45610MEDIUM6.5WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability o...
CVE-2026-45582MEDIUM6.5n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior...
CVE-2026-45580MEDIUM5.4WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability....
CVE-2026-40510MEDIUM6.8OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history...
CVE-2026-10075MEDIUM6.9DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read ...
CVE-2026-10074MEDIUM6.9DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing privileged local attackers to explo...
CVE-2026-49324MEDIUM4.6Uncontrolled resource consumption in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025...
CVE-2026-49323MEDIUM4.3Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcyc...
CVE-2026-45551MEDIUM5.1Group-Office is an enterprise customer relationship management and groupware tool. Prior to 26.0.25, 25.0.100, and 6.8.1...
CVE-2026-9811MEDIUM5.4A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering s...
CVE-2026-9557MEDIUM6.4A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of...
CVE-2026-42965MEDIUM6.5A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creat...
CVE-2026-9189MEDIUM5.3The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verifi...
CVE-2026-49198MEDIUM4.9Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorize...
CVE-2026-10058MEDIUM4.8ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now