2026 CVE Vulnerabilities

48,075 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-9798MEDIUM4.3A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily...
CVE-2026-9673MEDIUM6.8Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjec...
CVE-2026-9644MEDIUM6.4The LiveSmart Video Chat Live Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2026-7533MEDIUM4.3The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2026-3173MEDIUM6.5The Meta Field Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i...
CVE-2026-9796MEDIUM6.5A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check ...
CVE-2026-9794MEDIUM5.3A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially cra...
CVE-2026-9792MEDIUM6.5A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When cer...
CVE-2026-9791MEDIUM4.3A flaw was found in Keycloak. An authenticated user with existing organization membership can exploit this flaw by acces...
CVE-2026-9241MEDIUM4.3The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass Thro...
CVE-2026-9228MEDIUM4.3The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in ...
CVE-2026-5737MEDIUM6.5The Independent Analytics plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and i...
CVE-2026-4888MEDIUM4.3The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to...
CVE-2026-46544MEDIUM5.3Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Micro...
CVE-2026-46538MEDIUM5.9Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Micro...
CVE-2026-46416MEDIUM6.3Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Micro...
CVE-2026-44720MEDIUM6.9OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to 2.0.4, a critical authentication ...
CVE-2026-47270MEDIUM6.3pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb is a PAM modu...
CVE-2026-44710MEDIUM4.6pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, src/device.c passed t...
CVE-2026-21785MEDIUM4A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlie...
CVE-2026-9759MEDIUM5.5ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service
CVE-2026-48792MEDIUM4.4pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/evdev.c silently ...
CVE-2026-48066MEDIUM5.7pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/log.c contains a ...
CVE-2026-48065MEDIUM6.7pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/conf.c allocates ...
CVE-2026-47274MEDIUM6.3pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, multiple pam_usb help...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now