2026 CVE Vulnerabilities

48,670 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-41662MEDIUM5.2Admidio is an open-source user management solution. Prior to version 5.0.9, Role::stopMembership() does not verify wheth...
CVE-2026-41661MEDIUM6.1Admidio is an open-source user management solution. Prior to version 5.0.9, an unauthenticated attacker can execute arbi...
CVE-2026-41658MEDIUM6.5Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio inventory module enforces author...
CVE-2026-41657MEDIUM4.9Admidio is an open-source user management solution. Prior to version 5.0.9, the contacts_data.php endpoint uses a weaker...
CVE-2026-41656MEDIUM4.5Admidio is an open-source user management solution. Prior to version 5.0.9, the add mode in modules/documents-files.php ...
CVE-2026-41655MEDIUM6.5Admidio is an open-source user management solution. Prior to version 5.0.9, the ecard_preview.php endpoint does not vali...
CVE-2026-41004MEDIUM4.4When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Sp...
CVE-2026-4807MEDIUM6.5The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and inclu...
CVE-2026-44600MEDIUM5.3Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-202...
CVE-2026-44599MEDIUM5.3Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.
CVE-2026-6222MEDIUM5.3The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1....
CVE-2026-40003MEDIUM6.8ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the l...
CVE-2026-41484MEDIUM5.9OpenTelemetry.Exporter.OneCollector is a .NET exporter that sends telemetry to a OneCollector back-end over HTTP. In ver...
CVE-2026-41483MEDIUM5.9OpenTelemetry.Resources.Azure is the .NET resource detector for Azure environments. In versions 1.15.0-beta.1 and earlie...
CVE-2026-41417MEDIUM5.3Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created f...
CVE-2026-41310MEDIUM5.3OpenTelemetry.Exporter.Zipkin is the .NET Zipkin exporter for OpenTelemetry. In versions 1.15.2 and earlier, the Zipkin ...
CVE-2026-40296MEDIUM5.4PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The HTML writer skips htmlspecialchars e...
CVE-2026-3291MEDIUM5.5Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated vers...
CVE-2026-40332MEDIUM5.3Masa CMS is affected by an Open Redirect vulnerability due to improper handling of scheme-relative URLs. The application...
CVE-2026-40251MEDIUM6.5Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora...
CVE-2026-40243MEDIUM4.8Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OV...
CVE-2026-40197MEDIUM6.5Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora...
CVE-2026-40195MEDIUM6.5Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora...
CVE-2026-8033MEDIUM5.5A vulnerability has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. This affects an unknown function of t...
CVE-2026-44117MEDIUM6.3OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in QQBot direct media upload that skips U...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now