2026 CVE Vulnerabilities

48,516 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-8096MEDIUM6.5The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypa...
CVE-2026-34154MEDIUM5.3Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1...
CVE-2026-33741MEDIUM6.8EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated use...
CVE-2026-33637MEDIUM6.5Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Versions 2.0.0 ...
CVE-2026-32738MEDIUM6.5libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequen...
CVE-2026-32134MEDIUM5.9NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In versions 0.24.10 and below, when NanoMQ handles...
CVE-2026-36827MEDIUM5.4A command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web management interface inv...
CVE-2026-8706MEDIUM6.5Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same devi...
CVE-2026-45557MEDIUM6.9Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records. An attacker in con...
CVE-2026-34883MEDIUM5.3An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell monitors. On Windows, a ...
CVE-2026-8971MEDIUM6.5Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird ...
CVE-2026-8961MEDIUM6.5Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderb...
CVE-2026-8951MEDIUM6.5Spoofing issue in the Toolbar component in Firefox for Android. This vulnerability was fixed in Firefox 151.
CVE-2026-23557MEDIUM6.5Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() tri...
CVE-2026-4630MEDIUM6.8A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerabi...
CVE-2026-45442MEDIUM4.3Missing Authorization vulnerability in Brainstorm Force Presto Player allows Exploiting Incorrectly Configured Access Co...
CVE-2026-43492MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: lib/crypto: mpi: Fix integer underflow in mpi_read_...
CVE-2026-43491MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: qrtr: ns: Limit the maximum server registratio...
CVE-2026-37982MEDIUM6.8A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsAction...
CVE-2026-37981MEDIUM4.3A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows...
CVE-2026-37979MEDIUM6.5A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection ...
CVE-2026-37978MEDIUM4.9A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking th...
CVE-2026-46724MEDIUM5.9The file indexer does not normalize the configured directory path. A backend user with permission to edit indexer config...
CVE-2026-46723MEDIUM5.9The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backe...
CVE-2026-46722MEDIUM5.9The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document place...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now