2026 CVE Vulnerabilities

49,078 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-7423MEDIUM6.5Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adj...
CVE-2026-7397MEDIUM4.4A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path ...
CVE-2026-41499MEDIUM6.5Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to befo...
CVE-2026-26206MEDIUM6.5Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to befo...
CVE-2026-7396MEDIUM5.5A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality ...
CVE-2026-7394MEDIUM4.7A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is an unkn...
CVE-2026-26204MEDIUM5.5Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 1.0.0 to befo...
CVE-2026-7393MEDIUM4.7A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function save_menu of the file...
CVE-2026-7392MEDIUM6.3A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function dele...
CVE-2026-7391MEDIUM6.3A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function save_supplier...
CVE-2026-6915MEDIUM4.3An authorization flaw in the user management command could allow an authenticated user to make limited changes to authen...
CVE-2026-0206MEDIUM4.9A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewal...
CVE-2026-0205MEDIUM6.8A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted ser...
CVE-2026-7388MEDIUM4.7A weakness has been identified in EyouCMS up to 1.7.9. Impacted is the function editFile of the file application/admin/l...
CVE-2026-40230MEDIUM5.4Helpy contains a stored cross-site scripting vulnerability in the knowledge base Doc rendering logic. An authenticated a...
CVE-2026-40229MEDIUM5.4Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can per...
CVE-2026-38993MEDIUM6.5Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows aut...
CVE-2026-2810MEDIUM6.8Netskope was notified about a potential gap in the Endpoint DLP Module for Netskope Client on Windows systems. The succe...
CVE-2026-25852MEDIUM6.7Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock D...
CVE-2026-42525MEDIUM4.3Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL...
CVE-2026-42522MEDIUM4.3A missing permission check in Jenkins GitHub Branch Source Plugin 1967.vdea_d580c1a_b_a_ and earlier allows attackers wi...
CVE-2026-42521MEDIUM6.5Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructor...
CVE-2026-42519MEDIUM4.3A missing permission check in Jenkins Script Security Plugin 1399.ve6a_66547f6e1 and earlier allows attackers with Overa...
CVE-2026-42648MEDIUM4.3Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrec...
CVE-2026-42645MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Or...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now