2026 CVE Vulnerabilities

48,089 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-46424MEDIUM4.2Budibase is an open-source low-code platform. Prior to 3.38.2, the public API role unassignment endpoint (POST /api/publ...
CVE-2026-45719MEDIUM6.5Budibase is an open-source low-code platform. Prior to 3.38.1, the V1 Views API (POST /api/views) accepts a calculation ...
CVE-2026-45718MEDIUM5.4Budibase is an open-source low-code platform. Prior to 3.38.1, the row action trigger endpoint (POST /api/tables/:source...
CVE-2026-45081MEDIUM6.5Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.5.0, authenticated employees could a...
CVE-2026-42328MEDIUM6.2go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec ...
CVE-2026-38808MEDIUM5.3SQL Injection vulnerability in uzy-ssm-mall v1.1.0 allows a remote attacker to obtain sensitive information via the Prod...
CVE-2026-49054MEDIUM4.3Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly Configured Access Cont...
CVE-2026-45335MEDIUM5.4WeGIA is a web manager for charitable institutions. Prior to 3.7.3, an Open Redirect vulnerability was identified in the...
CVE-2026-45027MEDIUM5.9WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, when a user logs in, html/login.php hash...
CVE-2026-44475MEDIUM6.1Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core does not verify the UE Security Capabil...
CVE-2026-44353MEDIUM6.5Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.4.0, Streaml...
CVE-2026-44324MEDIUM6.5free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's UDR nudr-dr DELETE /subscript...
CVE-2026-44323MEDIUM6.5free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's UDR nudr-dr DELETE /subscript...
CVE-2026-44318MEDIUM5.3free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's BSF PUT /nbsf-management/v1/s...
CVE-2026-44317MEDIUM6.5free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's PCF POST /npcf-policyauthoriz...
CVE-2026-42082MEDIUM5.4free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not enforce the...
CVE-2026-38931MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp ...
CVE-2026-38930MEDIUM6.5OpenRapid RapidCMS v1.3.1 was discovered to contain an authentication bypass in the /template/default/menu.php component...
CVE-2026-9674MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows atta...
CVE-2026-6957MEDIUM4.9Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to constr...
CVE-2026-49102MEDIUM6.1Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes compo...
CVE-2026-49059MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing. ...
CVE-2026-49053MEDIUM5.3Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured ...
CVE-2026-49052MEDIUM4.3Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured ...
CVE-2026-49051MEDIUM4.3Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now