2026 CVE Vulnerabilities

48,516 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-46721MEDIUM6.9The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on th...
CVE-2026-45187MEDIUM6.5Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users...
CVE-2026-35086MEDIUM6.5Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue a...
CVE-2026-31906MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz. Thi...
CVE-2026-31388MEDIUM5.3Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affects Apache OFBiz: bef...
CVE-2026-31387MEDIUM5.3Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are rec...
CVE-2026-31380MEDIUM6.5Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') v...
CVE-2026-31379MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname ...
CVE-2026-31378MEDIUM6.5Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are r...
CVE-2026-29220MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issu...
CVE-2026-29207MEDIUM6.5Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects...
CVE-2026-44408MEDIUM6.3There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an...
CVE-2026-8922MEDIUM5.4A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies are configured, Key...
CVE-2026-8830MEDIUM4.3A flaw was found in Keycloak. An authenticated user can bypass configured WebAuthn policies during credential registrati...
CVE-2026-8814MEDIUM5.5Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amp...
CVE-2026-32994MEDIUM5.3The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.8,...
CVE-2026-28733MEDIUM6.5in OpenHarmony v6.0 and prior versions allow a local attacker arbitrary code execution.
CVE-2026-27766MEDIUM5.5in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak.
CVE-2026-25850MEDIUM5.5in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak
CVE-2026-33514MEDIUM4.3Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1...
CVE-2026-33234MEDIUM5AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-33052MEDIUM5.3Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.0 and 2.28.1 allow a low-privileged authent...
CVE-2026-32312MEDIUM4.3GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with f...
CVE-2026-32244MEDIUM5.3Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1...
CVE-2026-27892MEDIUM6.5FacturaScripts is an open source accounting and invoicing software. In versions prior to 2026, the Library module stores...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now