2026 CVE Vulnerabilities

48,325 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-20240MEDIUM6.5In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.26...
CVE-2026-20239MEDIUM6.5In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.1...
CVE-2026-20238MEDIUM6.5In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could a...
CVE-2026-9101MEDIUM5.3Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering she...
CVE-2026-9100MEDIUM6The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. ...
CVE-2026-44924MEDIUM5.4InfoScale VIOM 9.1.3 allows XSS.
CVE-2026-44923MEDIUM6.5SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges.
CVE-2026-20206MEDIUM6.3A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, ...
CVE-2026-20171MEDIUM6.8A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switc...
CVE-2026-9084MEDIUM6MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based ...
CVE-2026-4293MEDIUM5.3The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be ...
CVE-2026-21836MEDIUM6.5The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability.  Under certain circumstances, documen...
CVE-2026-5950MEDIUM5.3An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling ...
CVE-2026-5947MEDIUM5.9Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incomi...
CVE-2026-45443MEDIUM5Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Explo...
CVE-2026-3592MEDIUM5.3BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a quer...
CVE-2026-27424MEDIUM4.3Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiting Incorrectly Confi...
CVE-2026-27405MEDIUM6.5Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Contr...
CVE-2026-24573MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualiz...
CVE-2026-25602MEDIUM4.4Insufficient Verification of Data Authenticity vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona S...
CVE-2026-0857MEDIUM6Cleartext Storage of Sensitive Information in Memory vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo M...
CVE-2026-6728MEDIUM5.3The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includ...
CVE-2026-44608MEDIUM5.9NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain...
CVE-2026-44390MEDIUM5.3NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets t...
CVE-2026-42923MEDIUM5.3NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator where the code path to...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now