2026 CVE Vulnerabilities

50,066 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-3885MEDIUM6.4The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2026-3428MEDIUM5.4A Download of Code Without Integrity Check vulnerability in the update modules in ASUS Member Center(华硕大厅) allows a loca...
CVE-2026-1880MEDIUM5.4An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privi...
CVE-2026-40505MEDIUM4.8MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI esca...
CVE-2026-3299MEDIUM6.4The WP YouTube Lyte plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lyte' shortcode ...
CVE-2026-4949MEDIUM4.3The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres...
CVE-2026-40179MEDIUM6.1Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3....
CVE-2026-39350MEDIUM5.4Istio is an open platform to connect, manage, and secure microservices. In versions 1.25.0 through 1.27.8, 1.28.0 throug...
CVE-2026-1711MEDIUM4.8Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interf...
CVE-2026-1564MEDIUM4.8Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface componen...
CVE-2026-40186MEDIUM6.1ApostropheCMS is an open-source Node.js content management system. A regression introduced in commit 49d0bb7, included i...
CVE-2026-6385MEDIUM6.5A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/...
CVE-2026-6364MEDIUM6.5Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sens...
CVE-2026-6362MEDIUM4.3Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out o...
CVE-2026-6298MEDIUM4.3Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially se...
CVE-2026-40919MEDIUM5.5A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited...
CVE-2026-40918MEDIUM5.5A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of se...
CVE-2026-40916MEDIUM5.5A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a lo...
CVE-2026-39857MEDIUM5.3ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization by...
CVE-2026-33889MEDIUM5.4ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site...
CVE-2026-33888MEDIUM5.3ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization by...
CVE-2026-21726MEDIUM5.3The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by doub...
CVE-2026-6383MEDIUM5.4A flaw was found in KubeVirt's Role-Based Access Control (RBAC) evaluation logic. The authorization mechanism improperly...
CVE-2026-6245MEDIUM5.5A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PA...
CVE-2026-40256MEDIUM5Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string pre...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now