2026 CVE Vulnerabilities

50,042 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-40515MEDIUM5.5OpenHarness before commit bd4df81 contains a permission bypass vulnerability that allows attackers to read sensitive fil...
CVE-2026-6497MEDIUM6.3A vulnerability was determined in prasathmani TinyFileManager up to 2.6. Affected by this vulnerability is an unknown fu...
CVE-2026-21709MEDIUM6.7A vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement.
CVE-2026-6496MEDIUM5.4A vulnerability was found in prasathmani TinyFileManager up to 2.6. Affected is an unknown function of the file /fileman...
CVE-2026-6492MEDIUM5.5A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea....
CVE-2026-6491MEDIUM5.3A security vulnerability has been detected in libvips up to 8.18.2. The affected element is the function im_minpos_vec o...
CVE-2026-40458MEDIUM6.5PAC4J is vulnerable to Cross-Site Request Forgery (CSRF). A malicious attacker can craft a specially designed website wh...
CVE-2026-6489MEDIUM6.3A security flaw has been discovered in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This issue affects ...
CVE-2026-6488MEDIUM6.3A vulnerability was identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This vulnerability affec...
CVE-2026-6487MEDIUM4.3A flaw has been found in Qihui jtbc5 CMS 5.0.3.6. Affected is an unknown function of the file /dev/code/common/diplomat/...
CVE-2026-28263MEDIUM4.8Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,...
CVE-2026-23777MEDIUM6.5Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,...
CVE-2026-5131MEDIUM6.9GREENmod uses named pipes for communication between plugins, the web portal, and the system service, but the access cont...
CVE-2026-35153MEDIUM6.7Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers...
CVE-2026-35074MEDIUM6.7Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers...
CVE-2026-35073MEDIUM6.7Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers...
CVE-2026-35072MEDIUM6.7Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers...
CVE-2026-23779MEDIUM6.7Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,...
CVE-2026-6494MEDIUM5.3A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by ...
CVE-2026-6439MEDIUM4.4The VideoZen plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.1. Th...
CVE-2026-23775MEDIUM5.7Dell PowerProtect Data Domain appliances with Data Domain Operating System (DD OS) of Feature Release versions 8.0 throu...
CVE-2026-6451MEDIUM4.3The cms-fuer-motorrad-werkstaetten plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to an...
CVE-2026-6441MEDIUM4.3The Canto plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 3.1.1. This is due...
CVE-2026-5797MEDIUM5.3The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and inc...
CVE-2026-35496MEDIUM5.1A path traversal vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privileg...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now