2026 CVE Vulnerabilities

64,779 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-54644MEDIUM6.1CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip...
CVE-2026-54643MEDIUM5.4CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete-note handler in admin/sources/orders.index.inc.ph...
CVE-2026-54642MEDIUM5.3CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored-...
CVE-2026-54633MEDIUM6.9PoDoFo is a C++17 PDF manipulation library. From version 1.0.0 until 1.1.1, processing a crafted PDF with an Indexed col...
CVE-2026-54613MEDIUM5.4Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5...
CVE-2026-53556MEDIUM6SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/dat...
CVE-2026-53555MEDIUM5.1SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated upl...
CVE-2026-50291MEDIUM5.5OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a...
CVE-2026-16750MEDIUM5.3The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of da...
CVE-2026-16582MEDIUM5.3The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modificatio...
CVE-2026-14311MEDIUM5.4The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and ...
CVE-2026-93395MEDIUM5.3A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when proc...
CVE-2026-93387MEDIUM4.3Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-orig...
CVE-2026-93386MEDIUM5.4UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging soci...
CVE-2026-93385MEDIUM6.5Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive informat...
CVE-2026-93383MEDIUM4.3Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin d...
CVE-2026-93379MEDIUM4.3Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolatio...
CVE-2026-93376MEDIUM6.3Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social en...
CVE-2026-77281MEDIUM6.5Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-depe...
CVE-2026-67071MEDIUM6.5HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted proper...
CVE-2026-54918MEDIUM5.3NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the a...
CVE-2026-54907MEDIUM5.3Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates. Prior to 1.5.1, Caddy...
CVE-2026-54604MEDIUM5.3OpenSlide is a C library for reading whole slide image files. Prior to 4.0.1, a behavior change in libtiff 4.7.1 causes ...
CVE-2026-54565MEDIUM4.7rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. Prior to rhwp 0.7.15 and rhwp Chrome and Firefox e...
CVE-2026-54521MEDIUM6.1FairEmail is a fully featured, open source, privacy-friendly email app for Android. Prior to 1.2319, the ActivityAMP AMP...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now