2026 CVE Vulnerabilities

48,280 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-41917MEDIUM6.9OpenKM 6.3.12 contains a local file inclusion vulnerability in the administrative scripting interface at /admin/Scriptin...
CVE-2026-9542MEDIUM6.3A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of ...
CVE-2026-9541MEDIUM5.3A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqob...
CVE-2026-9540MEDIUM5.5A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component ...
CVE-2026-8479MEDIUM6.9IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially craf...
CVE-2026-8174MEDIUM5.7Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue affects Zoho Mail wo...
CVE-2026-7310MEDIUM4.4A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious ...
CVE-2026-48136MEDIUM4.1When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access...
CVE-2026-48135MEDIUM5.3A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request pa...
CVE-2026-48134MEDIUM5.6When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific...
CVE-2026-39642MEDIUM5.3Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in SpabRice Nyla allows Code...
CVE-2026-27427MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mas...
CVE-2026-24638MEDIUM4.3Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Cont...
CVE-2026-24590MEDIUM5.3Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Config...
CVE-2026-39655MEDIUM5.3Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiting Incorrectly Configured Access Control...
CVE-2026-9534MEDIUM6.3A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cs...
CVE-2026-9533MEDIUM6.3A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of th...
CVE-2026-9532MEDIUM6.3A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploa...
CVE-2026-3314MEDIUM4.6Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view, Hi...
CVE-2026-9531MEDIUM6.3A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUboot of the file /cgi...
CVE-2026-9527MEDIUM4.3A vulnerability was determined in itsourcecode Electronic Judging System 1.0. This issue affects some unknown processing...
CVE-2026-9524MEDIUM6.3A flaw has been found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is the function execute of...
CVE-2026-9520MEDIUM4.3A weakness has been identified in blitz-js blitz up to 3.0.2 on GitHub. This impacts an unknown function of the file pac...
CVE-2026-9519MEDIUM4.3A security flaw has been discovered in stonith404 pingvin-share up to 1.13.0. This affects the function getServerSidePro...
CVE-2026-9518MEDIUM4.3A vulnerability was identified in hemant6488 CodeIgniter-StudentManagementSystem. The impacted element is the function a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now