2026 CVE Vulnerabilities

50,042 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-40479MEDIUM5.4Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in Ki...
CVE-2026-2434MEDIUM6.4The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attribute...
CVE-2026-40353MEDIUM5.4wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the attribution_link property in Abs...
CVE-2026-40306MEDIUM6.5DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new in...
CVE-2026-40305MEDIUM4.3DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting i...
CVE-2026-40304MEDIUM5.3zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the unaccess handler (c...
CVE-2026-40302MEDIUM6.1zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template en...
CVE-2026-40301MEDIUM4.7DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style...
CVE-2026-40299MEDIUM6.9next-intl provides internationalization for Next.js. Applications using the `next-intl` middleware prior to version 4.9....
CVE-2026-40293MEDIUM6.5OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is co...
CVE-2026-40284MEDIUM6.8WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vul...
CVE-2026-40282MEDIUM6.4WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vul...
CVE-2026-40155MEDIUM5.4The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 thro...
CVE-2026-33436MEDIUM6.1Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. In versions prior to ...
CVE-2026-33145MEDIUM6.3xrdp is an open source RDP server. Versions through 0.10.5 allow an authenticated remote user to execute arbitrary comma...
CVE-2026-35061MEDIUM5.3Anviz CX7 Firmware is vulnerable to the most recently captured test photo that can be retrieved without authentication,...
CVE-2026-33569MEDIUM6.5Anviz CX2 Lite and CX7 administrative sessions occur over HTTP, enabling on‑path attackers to sniff credentials and ses...
CVE-2026-33093MEDIUM5.3Anviz CX7 Firmware is vulnerable to an unauthenticated POST to the device that captures a photo with the front facing c...
CVE-2026-32648MEDIUM5.3Anviz CX2 Lite and CX7 are vulnerable to unauthenticated access that discloses debug configuration details (e.g., SSH/R...
CVE-2026-32624MEDIUM6.5xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in its log...
CVE-2026-31927MEDIUM4.9Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files...
CVE-2026-6437MEDIUM6.9Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-drive...
CVE-2026-28214MEDIUM6.5Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the Clum...
CVE-2026-40319MEDIUM5.5Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the RegexMatching check passes ...
CVE-2026-40516MEDIUM6.3OpenHarness before commit bd4df81 contains a server-side request forgery vulnerability in the web_fetch and web_search t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now