2026 CVE Vulnerabilities

43,273 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-18651MEDIUM5.4A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind cr...
CVE-2026-18508MEDIUM4.4A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confin...
CVE-2026-15430MEDIUM6.2Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, ...
CVE-2026-69094MEDIUM5.3Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_fu...
CVE-2026-69092MEDIUM6.9Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echo...
CVE-2026-69090MEDIUM6.9Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role adm...
CVE-2026-68585MEDIUM6.9SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that r...
CVE-2026-56609MEDIUM6.5HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using...
CVE-2026-56608MEDIUM5.3HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular acce...
CVE-2026-68742MEDIUM5.5A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen ...
CVE-2026-69075MEDIUM6.9FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlled or administrator-c...
CVE-2026-63563MEDIUM6.9Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication ...
CVE-2026-62416MEDIUM6.9Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, requir...
CVE-2026-60011MEDIUM6.9Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image...
CVE-2026-8794MEDIUM6.9PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote atta...
CVE-2026-8793MEDIUM6.9PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticat...
CVE-2026-28147MEDIUM5.4Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templa...
CVE-2026-18593MEDIUM5.6A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/te...
CVE-2026-18592MEDIUM4.7A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of ...
CVE-2026-18590MEDIUM6.3A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file ad...
CVE-2026-12259MEDIUM5.3In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to ...
CVE-2026-16565MEDIUM4.3The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify produc...
CVE-2026-16564MEDIUM4.3The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ...
CVE-2026-16563MEDIUM6.5The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when return...
CVE-2026-16297MEDIUM4.1The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-impor...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now