2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-10832MEDIUM5.9A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaus...
CVE-2026-93602MEDIUM4.4rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares onl...
CVE-2026-93596MEDIUM4.3ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the Datab...
CVE-2026-93595MEDIUM6.5ArcadeDB before 26.9.1 contains an access control bypass vulnerability in the query_database tool exposed through the AI...
CVE-2026-93504MEDIUM6.3A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+se...
CVE-2026-93018MEDIUM5.5Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes pas...
CVE-2026-79294MEDIUM6.1Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbi...
CVE-2026-62282MEDIUM6.5OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack int...
CVE-2026-93492MEDIUM5.3A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames wi...
CVE-2026-93578MEDIUM5.9A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSP...
CVE-2026-93561MEDIUM6.5A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and ...
CVE-2026-92976MEDIUM5.1A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T-Systems’ TAO 2.0 suite. A...
CVE-2026-90884MEDIUM5.4The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' parameter in all v...
CVE-2026-15797MEDIUM6.4The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress ...
CVE-2026-56592MEDIUM6.5HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate a...
CVE-2026-56590MEDIUM6.4HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation c...
CVE-2026-4036MEDIUM6.5An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Sharing API in ...
CVE-2026-40537MEDIUM4.3A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-...
CVE-2026-40536MEDIUM4.3An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology...
CVE-2026-40535MEDIUM6.5An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synolo...
CVE-2026-40534MEDIUM5.4An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in Sy...
CVE-2026-40533MEDIUM5.3An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (...
CVE-2026-40532MEDIUM6.5A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-...
CVE-2026-40531MEDIUM4.3An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-690...
CVE-2026-21848MEDIUM5HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now