2026 CVE Vulnerabilities

49,638 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-1923MEDIUM6.4The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’...
CVE-2026-6878MEDIUM5.6A vulnerability was identified in ByteDance verl up to 0.7.0. Affected is the function math_equal of the file prime_math...
CVE-2026-6874MEDIUM4.3A vulnerability was determined in ericc-ch copilot-api up to 0.7.0. This impacts an unknown function of the file /token ...
CVE-2026-5926MEDIUM6.5IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ...
CVE-2026-4919MEDIUM4.8IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows an administrative use...
CVE-2026-4918MEDIUM4.8IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability allows an administrat...
CVE-2026-4917MEDIUM4.9IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker ...
CVE-2026-3621MEDIUM5.9IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnera...
CVE-2026-1726MEDIUM4.8IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1 enables privilege escalation, allowing unauthori...
CVE-2026-1352MEDIUM6.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could...
CVE-2026-1274MEDIUM4.9IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access m...
CVE-2026-1272MEDIUM4.3IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user a...
CVE-2026-41314MEDIUM6.5pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior ...
CVE-2026-41313MEDIUM6.5pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior ...
CVE-2026-41312MEDIUM6.5pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior ...
CVE-2026-41177MEDIUM5.5Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the Sq...
CVE-2026-41168MEDIUM5.3pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior ...
CVE-2026-3837MEDIUM5.4An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution wh...
CVE-2026-34068MEDIUM6.8nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, ...
CVE-2026-34067MEDIUM6.5nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, ...
CVE-2026-6019MEDIUM6.1http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It ...
CVE-2026-3673MEDIUM5.4An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim ope...
CVE-2026-34066MEDIUM5.3nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. Prior to version 1.3.0, `HistoryStor...
CVE-2026-34062MEDIUM5.3nimiq-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `MessageCodec::read_request` and...
CVE-2026-41469MEDIUM5.2Beghelli Sicuro24 SicuroWeb does not enforce a Content Security Policy, allowing unrestricted loading of external JavaSc...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now