2026 CVE Vulnerabilities

49,039 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-33450MEDIUM5.5CVE-2026-33450 is an out of bounds read vulnerability in the Secure Access MacOS client prior to 14.50. Attackers with ...
CVE-2026-28532MEDIUM6.5FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing...
CVE-2026-7429MEDIUM4.6SSCMS v7.4.0 contains a reflected cross-site scripting vulnerability in the STL processing endpoint that allows attacker...
CVE-2026-40603MEDIUM6.5Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-35514MEDIUM6.5Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-32148MEDIUM5.9Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows dependency...
CVE-2026-36766MEDIUM5.4Multiple authenticated cross-site scripting (XSS) vulnerabilities in the XssHttpServletRequestWrapper class of shopizer ...
CVE-2026-36763MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint of SpringBlade v4.8.0 al...
CVE-2026-36761MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the /msg/msgInner/save endpoint of JeeSite v5.15.1 allows attackers...
CVE-2026-36764MEDIUM5A Server-Side Request Forgery (SSRF) in the /ureport/datasource/testConnection endpoint of SpringBlade v4.8.0 allows aut...
CVE-2026-36757MEDIUM4.3A Server-Side Request Forgery (SSRF) in the /plugins/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authentica...
CVE-2026-38940MEDIUM6.1Cross Site Scripting vulnerability in RafyMrX TOKO-ONLINE-ROTI v.1.0 allows a remote attacker to execute arbitrary code ...
CVE-2026-38939MEDIUM6.1Cross Site Scripting vulnerability in andrewtch88 mvc-ecommerce v.1.0 allows a remote attacker to execute arbitrary code...
CVE-2026-36759MEDIUM6.5A Server-Side Request Forgery (SSRF) in the /themes/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticat...
CVE-2026-36758MEDIUM4.3A Server-Side Request Forgery (SSRF) in the /themes/-/install-from-uri endpoint of halo v2.22.14 allows authenticated at...
CVE-2026-36756MEDIUM5.4A Server-Side Request Forgery (SSRF) in the /plugins/-/install-from-uri endpoint of halo v2.22.14 allows authenticated a...
CVE-2026-7500MEDIUM5.4When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled...
CVE-2026-7163MEDIUM5.5A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Mul...
CVE-2026-7382MEDIUM6.5Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized ...
CVE-2026-5080MEDIUM5.9Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely. The session id is generate...
CVE-2026-1493MEDIUM5.4LEX Baza Dokumentów is vulnerable to DOM-based XSS in "em" cookie parameter. The application unsafely processes the para...
CVE-2026-31692MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: rtnetlink: add missing netlink_ns_capable() check f...
CVE-2026-6498MEDIUM5.3The Five Star Restaurant Reservations plugin for WordPress is vulnerable to a payment bypass via PHP type juggling in ve...
CVE-2026-42800MEDIUM5.3NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Mani...
CVE-2026-41016MEDIUM5.9Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certif...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now