2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-18531MEDIUM5.3IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use ...
CVE-2026-15656MEDIUM4.3IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cook...
CVE-2026-12762MEDIUM5.3IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensiti...
CVE-2026-16100MEDIUM6.5A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error...
CVE-2026-16071MEDIUM5.4A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external direc...
CVE-2026-7456MEDIUM6.5The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec...
CVE-2026-71293MEDIUM6.2Statamic CMS's user-augmentation resolver, AugmentedUser::get in src/Auth/AugmentedUser.php, contains an explicit case f...
CVE-2026-71286MEDIUM6.1The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its property...
CVE-2026-71283MEDIUM4.9Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), calls tarfile...
CVE-2026-71282MEDIUM6.5ChirpStack's SQLite-backend device tag filtering (chirpstack/src/storage/device.rs, in both get_count and list) interpol...
CVE-2026-71275MEDIUM5.4OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML r...
CVE-2026-71273MEDIUM6.5OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a plain GET request w...
CVE-2026-71260MEDIUM6.5ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (espho...
CVE-2026-71227MEDIUM5.1A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO...
CVE-2026-71225MEDIUM6.5A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stat...
CVE-2026-0516MEDIUM6.5A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to...
CVE-2026-71251MEDIUM6.5Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at uploads/{id}/download...
CVE-2026-71250MEDIUM4.3Firefly III's webhook URL validator (IsValidWebhookUrl.php) filters most private/reserved IPv4 ranges but contains an ex...
CVE-2026-71249MEDIUM6.1299Ko's public contact form (plugin/contact/controllers/ContactController.php, home) sets raw POST field values (name, f...
CVE-2026-71247MEDIUM6.5Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role t...
CVE-2026-71246MEDIUM4.3Pixelfed's SearchController (behind the auth middleware) accepts a URL via its remote-search parameters and fetches it s...
CVE-2026-71244MEDIUM6.5Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, r...
CVE-2026-71240MEDIUM4.3DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or sta...
CVE-2026-14574MEDIUM6.5In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` rec...
CVE-2026-14304MEDIUM5.5In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now