2026 CVE Vulnerabilities

48,516 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-5293MEDIUM6.4The 診断ジェネレータ作成プラグイン (Diagnosis Generator) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'js'...
CVE-2026-43620MEDIUM5.5Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver...
CVE-2026-43617MEDIUM6.3Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access ...
CVE-2026-45585MEDIUM6.8Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". ...
CVE-2026-39309MEDIUM5.5Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas...
CVE-2026-35593MEDIUM6.8Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowled...
CVE-2026-34970MEDIUM5.3Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow a bugnote author to acces...
CVE-2026-34754MEDIUM4.3Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow an authenticated user to ...
CVE-2026-8493MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox In...
CVE-2026-6871MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Obfuscate a...
CVE-2026-6367MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core...
CVE-2026-6366MEDIUM6.6Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow...
CVE-2026-6365MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core...
CVE-2026-6095MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Orejime all...
CVE-2026-34744MEDIUM5.3Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior permit a user to list and downl...
CVE-2026-34600MEDIUM5.7Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.5.2...
CVE-2026-34579MEDIUM5.3Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior are vulnerable to Authorization...
CVE-2026-5090MEDIUM6.1Template::Plugin::HTML versions through 3.102 for Perl allows HTML and JavaScript to be injected. The html_filter funct...
CVE-2026-34390MEDIUM5.1Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior have a Privilege Escalation vul...
CVE-2026-34246MEDIUM4.8CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Sc...
CVE-2026-34233MEDIUM6.5CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, multiple admin controllers...
CVE-2026-34216MEDIUM6.6CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the admin settings update ...
CVE-2026-32814MEDIUM6.5libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid imag...
CVE-2026-42526MEDIUM5.3In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0...
CVE-2026-32739MEDIUM6.5libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequen...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now