2026 CVE Vulnerabilities

49,109 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-7388MEDIUM4.7A weakness has been identified in EyouCMS up to 1.7.9. Impacted is the function editFile of the file application/admin/l...
CVE-2026-40230MEDIUM5.4Helpy contains a stored cross-site scripting vulnerability in the knowledge base Doc rendering logic. An authenticated a...
CVE-2026-40229MEDIUM5.4Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can per...
CVE-2026-38993MEDIUM6.5Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows aut...
CVE-2026-2810MEDIUM6.8Netskope was notified about a potential gap in the Endpoint DLP Module for Netskope Client on Windows systems. The succe...
CVE-2026-25852MEDIUM6.7Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock D...
CVE-2026-42525MEDIUM4.3Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL...
CVE-2026-42522MEDIUM4.3A missing permission check in Jenkins GitHub Branch Source Plugin 1967.vdea_d580c1a_b_a_ and earlier allows attackers wi...
CVE-2026-42521MEDIUM6.5Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructor...
CVE-2026-42519MEDIUM4.3A missing permission check in Jenkins Script Security Plugin 1399.ve6a_66547f6e1 and earlier allows attackers with Overa...
CVE-2026-42648MEDIUM4.3Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrec...
CVE-2026-42645MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Or...
CVE-2026-42644MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper BetterDocs bette...
CVE-2026-42643MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP Image Wi...
CVE-2026-42642MEDIUM5.3Missing Authorization vulnerability in StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Sec...
CVE-2026-42641MEDIUM5.4Server-Side Request Forgery (SSRF) vulnerability in ILLID Share This Image share-this-image allows Server Side Request F...
CVE-2026-2902MEDIUM6.1The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2026-22745MEDIUM5.3Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More ...
CVE-2026-22740MEDIUM6.5A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some...
CVE-2026-4019MEDIUM5.3The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to unauthorized data access in all versions ...
CVE-2026-42412MEDIUM6.5Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control S...
CVE-2026-21023MEDIUM5.5Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local att...
CVE-2026-23773MEDIUM4.3Dell Disk Library for Mainframe, version(s) DLm 8700/2700 contain(s) a Server-Side Request Forgery (SSRF) vulnerability....
CVE-2026-7340MEDIUM4.3Integer overflow in ANGLE in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker to perform an ou...
CVE-2026-7318MEDIUM5.9A vulnerability was detected in elie mcp-project 0.1.0. The affected element is the function search_papers of the file r...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now