2026 CVE Vulnerabilities

48,546 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-20718MEDIUM5.4Incorrect default permissions for some Intel(R) NPU Driver software installers before version 32.0.100.4511 within Ring ...
CVE-2026-20717MEDIUM6.6Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User App...
CVE-2026-8368MEDIUM6.5LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirect...
CVE-2026-8109MEDIUM6.5An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authen...
CVE-2026-7431MEDIUM4.4An incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.8R6 allows a local a...
CVE-2026-5061MEDIUM4.7The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper tha...
CVE-2026-8391MEDIUM5.3Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Fir...
CVE-2026-8388MEDIUM6.5Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3, ...
CVE-2026-43930MEDIUM5.9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 ...
CVE-2026-42006MEDIUM4.3An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomple...
CVE-2026-40638MEDIUM6.7Dell PowerScale InsightIQ, versions 5.0.0 through 6.2.0, contains an execution with unnecessary privileges vulnerability...
CVE-2026-40020MEDIUM4.3Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_all...
CVE-2026-40016MEDIUM6.5Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits ...
CVE-2026-33603MEDIUM5.3Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This ...
CVE-2026-45215MEDIUM5.3Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Retrieve Emb...
CVE-2026-45212MEDIUM5.3Missing Authorization vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster wp-asset-clean-up allows Exploiting ...
CVE-2026-45210MEDIUM5.4Missing Authorization vulnerability in Broadstreet Broadstreet Ads broadstreet allows Exploiting Incorrectly Configured ...
CVE-2026-6813MEDIUM4.4The Continually plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ...
CVE-2026-6800MEDIUM4.4The FastBots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to,...
CVE-2026-41125MEDIUM6A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions), blu...
CVE-2026-33862MEDIUM6.1A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2...
CVE-2026-1934MEDIUM4.3The Motors – Car Dealership & Classified Listings plugin for WordPress is vulnerable to Payment Bypass via insecure user...
CVE-2026-7661MEDIUM6.4The Bootstrap Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `box` shortcode in all...
CVE-2026-7659MEDIUM6.4The Advanced Social Media Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `social` short...
CVE-2026-7626MEDIUM5.3The Slek Gateway for WooCommerce plugin for WordPress is vulnerable to Information Exposure in version 1.0. This is due ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now