2026 CVE Vulnerabilities

48,284 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-48589MEDIUM5.4Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In ...
CVE-2026-44598MEDIUM5.4With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vu...
CVE-2026-43828MEDIUM6.5Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue...
CVE-2026-43827MEDIUM6.5Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 ...
CVE-2026-24597MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart allows Cross Site Request Forgery. This ...
CVE-2026-24574MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Static HTML/CSS allows Cross Site Request Fo...
CVE-2026-24545MEDIUM4.3Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Contro...
CVE-2026-9498MEDIUM6.3A vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass ...
CVE-2026-9497MEDIUM6.3A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject ...
CVE-2026-9486MEDIUM4.3A security flaw has been discovered in SourceCodester Student Grades Management System 1.0. This affects an unknown part...
CVE-2026-9484MEDIUM6.3A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is...
CVE-2026-48849MEDIUM4.4In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored valu...
CVE-2026-48846MEDIUM6.5In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a...
CVE-2026-48845MEDIUM6.5In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for U...
CVE-2026-24546MEDIUM5.3Missing Authorization vulnerability in Ruben Garcia GamiPress allows Exploiting Incorrectly Configured Access Control Se...
CVE-2026-9483MEDIUM6.3A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the...
CVE-2026-9473MEDIUM6.3A vulnerability has been found in c-rick jimeng-mcp 1.10.0. Affected by this vulnerability is the function getFileConten...
CVE-2026-9472MEDIUM6.3A flaw has been found in dazeb markdown-downloader up to 3d4394b34b6c99d81af817623af55e3384df5a6a. Affected is the funct...
CVE-2026-27768MEDIUM6.6SQL Injection affecting the Access Manager role.
CVE-2026-9468MEDIUM6.3A security flaw has been discovered in dazeb cline-mcp-memory-bank up to 55c81b9cf6c16700983c84dc4cdea3cafa19a75f. The a...
CVE-2026-9467MEDIUM4.3A vulnerability was identified in debugmcp mcp-debugger up to 0.20.0. Impacted is the function handleGetSourceContext of...
CVE-2026-9466MEDIUM5.5A vulnerability was determined in Tiandy Easy7 Integrated Management Platform 7.17.0. This issue affects some unknown pr...
CVE-2026-42797MEDIUM4.9Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate ...
CVE-2026-9464MEDIUM4.7A vulnerability has been found in YunaiV yudao-cloud 2026.03. This affects the function IotDataSinkHttpConfig of the fil...
CVE-2026-9078MEDIUM5.4Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now